
CVE-2026-28684 python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv… https://www.cve.org/CVERecord?id=CVE-2026-28684
Post summary
The text discloses that python-dotenv, before version 1.2.2, can read .env files and set environment variables via set_key() and unset_key(), and upgrading to 1.2.2 resolves the issue.

