CVE-2026-5271
pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current
pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. As a result, if a user executes a pymanager-generated command (e.g., pip, pytest) from an attacker-controlled directory, a malicious module in that directory can be imported and executed instead of the intended package.
HIGH · CVSS 7.8
EPSS 0.0002
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0