๐Ÿ” CVE Alert

CVE-2026-68939

UNKNOWN 0.0

Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.

CWE CWE-78 CWE-88 CWE-155
Vendor pyenv
Product pyenv
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for pyenv pyenv

Be the first to know when new unknown vulnerabilities affecting pyenv pyenv are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

pyenv / pyenv
< 2.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pyenv/pyenv/security/advisories/GHSA-g478-f579-9vp9 github.com: https://github.com/pyenv/pyenv/commit/95df7dbc7b34595b47c9b922de198547effda819 github.com: https://github.com/pyenv/pyenv/releases/tag/v2.8.0