OVERVIEW CVE-2026-28684 is a symbolic link following vulnerability in python-dotenv versions prior to 1.2.2. The `set_key()` and `unset_key()` functions improperly handle symbolic links when rewriting `.env` files, enabling local attackers to overwrite arbitrary files on the system when a cross-device rename fallback is triggered. This vulnerability affects any application utilizing python-dotenv for environment variable management. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.6 MEDIUM with a local attack vector, low attack complexity, and low privilege requirements. It requires user interaction and poses high integrity and availability impacts, as attackers can overwrite arbitrary files. The attack is limited to local access only, with no confidentiality impact. The FAUCET Risk Score of 36.0 out of 100 and EPSS score of 0.00016 indicate moderate concern relative to the broader CVE landscape. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. No public exploit code is currently available. Community attention appears limited, consistent with the low EPSS score. Organizations should prioritize patching to version 1.2.2 or apply the manual patch as a preventive measure rather than in response to active threats.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.2CPE matchmatch criteria | cpe:2.3:a:saurabh-kumar:python-dotenv:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.