PatchSiren

pyenv CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW pyenv CVE published 2026-08-18

CVE-2026-68939

Pyenv's is_version_safe() function and various commands are vulnerable to pathname expansion when handling .python-version values and PYENV_VERSION. This allows an attacker to select a different installed interpreter or version, potentially leading to security issues. The issue is fixed in version 2.8.0. Defenders should assess their exposure and take necessary actions to mitigate the vulnerability. The v [truncated]