CVE-2026-5271 is a search path hijacking vulnerability in pymanager, where the application includes the current working directory in its module search path. This allows a malicious module in an attacker-controlled directory to be imported and executed instead of the intended package if a user runs a pymanager-generated command from that location. Rated with a CVSSv4 score of 5.6 Medium, this vulnerability requires local access and user interaction to exploit, with low attack complexity, potentially leading to high integrity impact through arbitrary code execution. There is currently no evidence of active exploitation, nor are public exploit codes available in common repositories, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 26.0, < 26.1CPE match | cpe:2.3:a:python:pymanager:*:*:*:*:*:*:*:* | ||
26.0CPE matchmatch criteria | cpe:2.3:a:python:pymanager:26.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.