{"id":"CVE-2022-35861","details":"pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a Python version string in .python-version to execute shims under their control. (Shims are executables that pass a command along to a specific version of pyenv. The version string is used to construct the path to the command, and there is no validation of whether the version specified is a valid version. Thus, relative path traversal can occur.)","modified":"2026-08-12T03:30:29.885303543Z","published":"2022-07-17T16:31:03Z","related":["openSUSE-SU-2022:10183-1","openSUSE-SU-2024:12200-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35861.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35861.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35861"},{"type":"FIX","url":"https://github.com/pyenv/pyenv/commit/22fa683571d98b59ea16e5fe48ac411c67939653"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pyenv/pyenv","events":[{"introduced":"80e418eca535b9c7cbdd0f8557586eaaf872000d"},{"fixed":"22fa683571d98b59ea16e5fe48ac411c67939653"}],"database_specific":{"cpe":"cpe:2.3:a:pyenv:pyenv:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.24"},{"last_affected":"2.3.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.2","v2.3.1","v2.3.0","v2.2.5","v2.2.4-1","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.0.7","v2.0.6","v2.0.5","v2.0.4","v2.0.3","v2.0.2","v2.0.1","v2.0.0","v2.0.0-rc1","1.2.27","v1.2.26","1.2.26","v1.2.25","1.2.25","v1.2.24.1","1.2.24.1","v1.2.24","1.2.24"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-35861.json"}}],"schema_version":"1.9.0"}