CVE-2026-68939
Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.
| CWE | CWE-78 CWE-88 CWE-155 |
| Vendor | pyenv |
| Product | pyenv |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for pyenv pyenv
Be the first to know when new unknown vulnerabilities affecting pyenv pyenv are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
pyenv / pyenv
< 2.8.0