Skip to content
appaloosa scout logo main rounded
N/A

CVE-2008-5983

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

EPSS 0.1% percentile 30.3%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
python python Windows <2.6.6 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.1.0 <3.1.3 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
View on NVD ↗