CVE Feed

    Dashboard / CVE / CVE-2026-28684

    CVE-2026-28684

    python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.

    Published:Apr 20, 2026
    Last Modified:Apr 27, 2026
    EPS:Apr 20, 2026
    EPSS Score:0.00016
    CVSS Score:6.6

    Affected Products

    Vendor
    Saurabh-kumar
    Product
    Python-dotenv
    Vendor
    Theskumar
    Product
    Python-dotenv

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High