LOW
pyenv
CVE published 2026-08-18
CVE-2026-68939
Pyenv's is_version_safe() function and various commands are vulnerable to pathname expansion when handling .python-version values and PYENV_VERSION. This allows an attacker to select a different installed interpreter or version, potentially leading to security issues. The issue is fixed in version 2.8.0. Defenders should assess their exposure and take necessary actions to mitigate the vulnerability. The v [truncated]