Synced 18 Jun 2026 05:58 UTC Account
← All products

CVE-2008-5983

MEDIUM severity · CVSS 6.9 · Untrusted search path
6.9CVSS MEDIUM

Summary

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

Impact & exploitability

Attack vectorLocal
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impact
Exploit probability (EPSS)1%

AV:L/AC:M/Au:N/C:C/I:C/A:C

Affected products we track (2)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.