PT-2026-77145 · Pyenv · Pyenv

CVE-2026-68939

·

Published

2026-08-18

·

Updated

2026-08-26

CVSS v4.0

2.0

Low

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pyenv versions prior to 2.8.0
Description The is version safe() function in libexec/pyenv-version-file-read accepts shell glob metacharacters within .python-version values. Additionally, unquoted PYENV VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions performs pathname expansion against the current directory. This allows an attacker to use a matching file to silently select a different installed interpreter or version.
Recommendations Update Pyenv to version 2.8.0.

Exploit

Fix

Improper Neutralization of Wildcards

OS Command Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68939
GHSA-G478-F579-9VP9
OPENSUSE-SU-2026:11613-1
OPENSUSE-SU-2026:21664-1

Affected Products

Pyenv