Low severityNVD Advisory· Published Aug 18, 2026· Updated Sep 18, 2026
CVE-2026-68939
CVE-2026-68939
Description
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/pyenv&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/pyenv&distro=openSUSE%20Tumbleweed
< 2.4.14-bp160.2.1+ 1 more
- (no CPE)range: < 2.4.14-bp160.2.1
- (no CPE)range: < 2.8.4-1.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.