CVE-2026-68939
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.
Scoring
- Severity
- LOW
- CVSS base score
- 2
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-78, CWE-88, CWE-155
- Published
- 2026-08-18
- Last modified
- 2026-08-18
Affected products
- pyenv pyenv
Weakness type
Related vulnerabilities
- CVE-2026-19136 — A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application,...
- CVE-2026-73694 — FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition
- CVE-2026-73693 — FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler
- CVE-2026-65639 — OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a...
- CVE-2026-65638 — Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated...
- CVE-2026-81468 — Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special...
- CVE-2026-81467 — Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special...
- CVE-2026-64837 — ICEcoder through 8.1 OS Command Injection via lib/properties.php