CVE-2026-5271Disclosure(python / pymanager)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. As a result, if a user executes a pymanager-generated command (e.g., pip, pytest) from an attacker-controlled directory, a malicious module in that directory can be imported and executed instead of the intended package.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pymanager

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-01); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
pymanager

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-01: 2Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 104-0104-0204-03
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-012
Disclosure2
2026-04-021
Disclosure1
2026-04-031
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-5271: Python Install Manager (pymanager): Script aliases search path hijack https://www.openwall.com/lists/oss-security/2026/04/01/5 leading to modules in the current working directory being able to override the intended module and execute code as the user. Affects Python Install Manager (for Windows).

    Post summary

    CVE-2026-5271 is disclosed as a search‑path hijack vulnerability in Python Install Manager that allows local modules to override intended modules and execute code as the user, with no mention of PoC, exploit, or active exploitation.

    02061731
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5271 pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. This could lead to modules g… https://www.cve.org/CVERecord?id=CVE-2026-5271

    Post summary

    CVE-2026-5271 in pymanager exposes the current working directory in sys.path, allowing module shadowing that could lead to unintended code execution.

    0001065
    56.9K followersView on X
  • ‘BBWriteups’@bbwriteup
    Disclosure

    "CWD-Based Module Hijacking in Python pymanager (CVE-2026-5271)" by LETCHU PKT #BugBounty #Cybersecurity #Hacking #InfoSec https://letchupkt.medium.com/cwd-based-module-hijacking-in-python-pymanager-cve-2026-5271-2fb57bbc65eb

    Post summary

    The tweet announces CVE-2026-5271, a CWD‑based module hijacking issue in Python’s pymanager, and links to a Medium article for further details.

    0000068
    563 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5271 - Possible to hijack modules in current working directory Intel Report: https://ift.tt/db0o7X2

    Post summary

    The post announces CVE-2026-5271, indicating a potential module hijack in the working directory, but offers no PoC, exploit, patch, or evidence of active attacks.

    0000020
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpymanager26.0--

Explore more