{"id":"CVE-2026-68939","summary":"Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)","details":"Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.","aliases":["GHSA-g478-f579-9vp9"],"modified":"2026-08-27T17:40:57.985458963Z","published":"2026-08-18T15:11:10.331Z","related":["openSUSE-SU-2026:11613-1","openSUSE-SU-2026:21664-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68939.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-155","CWE-78","CWE-88"]},"references":[{"type":"WEB","url":"https://github.com/pyenv/pyenv/releases/tag/v2.8.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68939.json"},{"type":"ADVISORY","url":"https://github.com/pyenv/pyenv/security/advisories/GHSA-g478-f579-9vp9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68939"},{"type":"FIX","url":"https://github.com/pyenv/pyenv/commit/95df7dbc7b34595b47c9b922de198547effda819"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pyenv/pyenv","events":[{"introduced":"0"},{"fixed":"95df7dbc7b34595b47c9b922de198547effda819"},{"fixed":"135adbb192d32142a648cae7c2f7e491f5c57202"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.8.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.7.3","v2.7.2","v2.7.1","v2.7.0","v2.6.31","v2.6.30","v2.6.29","v2.6.28","v2.6.27","v2.6.26","v2.6.25","v2.6.24","v2.6.23","v2.6.22","v2.6.21","v2.6.20","v2.6.19","v2.6.18","v2.6.17","v2.6.16","v2.6.15","v2.6.14","v2.6.13","v2.6.12","v2.6.11","v2.6.10","v2.6.9","v.2.6.9","v2.6.8","v2.6.7","v2.6.6","v2.6.5","v2.6.4","v2.6.3","v2.6.2","v2.6.1","v2.6.0","v2.5.7","v2.5.6","v2.5.5","v2.5.4","v2.5.3","v2.5.2","v2.5.1","v2.5.0","v2.4.23","v2.4.22","v2.4.21","v2.4.20","v2.4.19","v2.4.18","v2.4.17","v2.4.16","v2.4.15","v2.4.14","v2.4.13","v2.4.12","v2.4.11","v2.4.10","v2.4.9","v2.4.8","v2.4.7","v2.4.6","v2.4.5_1","v2.4.5","v2.4.4","v2.4.3","v2.4.2","r","v2.4.1","v2.4.0","v2.3.36","v2.3.35","v2.3.34","v2.3.33","v2.3.32","v2.3.31","2.3.30","v2.3.29","v2.3.28","v2.3.27","v2.3.26","v2.3.25","v2.3.24","v2.3.23","v2.3.22","v2.3.21","v2.3.20","v2.3.19","v2.3.18","v2.3.17","v2.3.16","v2.3.15","v2.3.14","v2.3.13","v2.3.12","v2.3.11","v2.3.10","v2.3.9","v2.3.8","v2.3.7","v2.3.6","v2.3.5","v2.3.4","v2.3.3","v2.3.2","v2.3.1","v2.3.0","v2.2.5","v2.2.4-1","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.0.7","v2.0.6","v2.0.5","v2.0.4","v2.0.3","v2.0.2","v2.0.1","v2.0.0","v2.0.0-rc1","1.2.27","v1.2.26","1.2.26","v1.2.25","1.2.25","v1.2.24.1","1.2.24.1","v1.2.24","1.2.24","v1.2.23","v1.2.22","v1.2.21","v1.2.20","v1.2.19","v1.2.18","v1.2.17","v1.2.16","v1.2.15","v1.2.14","v1.2.13","v1.2.12","v1.2.11","v1.2.10","v1.2.9","v1.2.8","v1.2.7","v1.2.6","v1.2.5","v1.2.4","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.5","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.10","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.0","v20160726","v20160629","v20160628","v20160509","v20160422","v20160303","v20160202","v20151222","v20151210","v20151124","v20151105","v20151103","v20151006","v20150913","v20150901","v20150719","v20150601","v20150524","v20150326","v20141211","v20150204","v20150124","v20141127","v20141118","v20141106","v20141012","v20141011","v20141008","v20140924","v20140825","v20140705","v20140628","v20140615","v20140614","v0.4.0-20140602","v0.4.0-20140520","v0.4.0-20140516","v0.4.0-20140404","v0.4.0-20140317","v0.4.0-20140311","v0.4.0-20140123","v0.4.0-20131217","v0.4.0-20131216","v0.4.0-20131116","v0.4.0-20131023","v0.4.0-20130726","v0.4.0-20130613","v0.2.0","v0.1.2","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68939.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}