
CVE-2026-5271: Python Install Manager (pymanager): Script aliases search path hijack https://www.openwall.com/lists/oss-security/2026/04/01/5 leading to modules in the current working directory being able to override the intended module and execute code as the user. Affects Python Install Manager (for Windows).
Post summary
CVE-2026-5271 is disclosed as a search‑path hijack vulnerability in Python Install Manager that allows local modules to override intended modules and execute code as the user, with no mention of PoC, exploit, or active exploitation.



