CVE-2026-68939

Source
https://cve.org/CVERecord?id=CVE-2026-68939
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68939.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68939
Aliases
  • GHSA-g478-f579-9vp9
Downstream
Related
Published
2026-08-18T15:11:10Z
Modified
2026-08-27T17:40:57Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)
Details

Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-155",
        "CWE-78",
        "CWE-88"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68939.json"
}
References

Affected packages

Git / github.com/pyenv/pyenv

Affected ranges

Type
GIT
Repo
https://github.com/pyenv/pyenv
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.8.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.2.24
1.2.24.1
1.2.25
1.2.26
1.2.27
2.*
2.3.30
Other
r
v20140614
v20140615
v20140628
v20140705
v20140825
v20140924
v20141008
v20141011
v20141012
v20141106
v20141118
v20141127
v20141211
v20150124
v20150204
v20150326
v20150524
v20150601
v20150719
v20150901
v20150913
v20151006
v20151103
v20151105
v20151124
v20151210
v20151222
v20160202
v20160303
v20160422
v20160509
v20160628
v20160629
v20160726
v.*
v.2.6.9
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.2.0
v0.4.0-20130613
v0.4.0-20130726
v0.4.0-20131023
v0.4.0-20131116
v0.4.0-20131216
v0.4.0-20131217
v0.4.0-20140123
v0.4.0-20140311
v0.4.0-20140317
v0.4.0-20140404
v0.4.0-20140516
v0.4.0-20140520
v0.4.0-20140602
v1.*
v1.0.0
v1.0.10
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.2.0
v1.2.1
v1.2.10
v1.2.11
v1.2.12
v1.2.13
v1.2.14
v1.2.15
v1.2.16
v1.2.17
v1.2.18
v1.2.19
v1.2.2
v1.2.20
v1.2.21
v1.2.22
v1.2.23
v1.2.24
v1.2.24.1
v1.2.25
v1.2.26
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.2.9
v2.*
v2.0.0
v2.0.0-rc1
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.4-1
v2.2.5
v2.3.0
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.19
v2.3.2
v2.3.20
v2.3.21
v2.3.22
v2.3.23
v2.3.24
v2.3.25
v2.3.26
v2.3.27
v2.3.28
v2.3.29
v2.3.3
v2.3.31
v2.3.32
v2.3.33
v2.3.34
v2.3.35
v2.3.36
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.16
v2.4.17
v2.4.18
v2.4.19
v2.4.2
v2.4.20
v2.4.21
v2.4.22
v2.4.23
v2.4.3
v2.4.4
v2.4.5
v2.4.5_1
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.5.1
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.6.0
v2.6.1
v2.6.10
v2.6.11
v2.6.12
v2.6.13
v2.6.14
v2.6.15
v2.6.16
v2.6.17
v2.6.18
v2.6.19
v2.6.2
v2.6.20
v2.6.21
v2.6.22
v2.6.23
v2.6.24
v2.6.25
v2.6.26
v2.6.27
v2.6.28
v2.6.29
v2.6.3
v2.6.30
v2.6.31
v2.6.4
v2.6.5
v2.6.6
v2.6.7
v2.6.8
v2.6.9
v2.7.0
v2.7.1
v2.7.2
v2.7.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68939.json"