Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-28684

24
FAUCET Score

OVERVIEW CVE-2026-28684 is a symbolic link following vulnerability in python-dotenv versions prior to 1.2.2. The `set_key()` and `unset_key()` functions improperly handle symbolic links when rewriting `.env` files, enabling local attackers to overwrite arbitrary files on the system when a cross-device rename fallback is triggered. This vulnerability affects any application utilizing python-dotenv for environment variable management. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.6 MEDIUM with a local attack vector, low attack complexity, and low privilege requirements. It requires user interaction and poses high integrity and availability impacts, as attackers can overwrite arbitrary files. The attack is limited to local access only, with no confidentiality impact. The FAUCET Risk Score of 36.0 out of 100 and EPSS score of 0.00016 indicate moderate concern relative to the broader CVE landscape. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. No public exploit code is currently available. Community attention appears limited, consistent with the low EPSS score. Organizations should prioritize patching to version 1.2.2 or apply the manual patch as a preventive measure rather than in response to active threats.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.2.2CPE matchmatch criteria
cpe:2.3:a:saurabh-kumar:python-dotenv:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

6.6MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 58th percentile among its peer group of 381 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: python-dotenvFixed in: 1.2.2

Vendor Advisories (1)

pipGHSA-mf9w-mj56-hr94medium

python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback

Apr 21, 2026

References

github.com / theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311
Patch
github.com / theskumar/python-dotenv/releases/tag/v1.2.2
Release Notes
github.com / theskumar/python-dotenv/security/advisories/GHSA-mf9w-mj56-hr94
ExploitPatchVendor Advisory