The Lab · 2026-04-21 19:23:00 · GitHub Issues
A critical security flaw in the widely-used python-dotenv library has been patched, exposing applications to arbitrary file overwrite attacks. The vulnerability, tracked as CVE-2026-28684 and GHSA-mf9w-mj56-hr94, resides in the `set_key()` and `unset_key()` functions. These functions, responsible for modifying `.env` f...
The Lab · 2026-04-21 19:23:05 · GitHub Issues
A critical security vulnerability in the widely-used python-dotenv library exposes systems to arbitrary file overwrite attacks. The flaw, tracked as CVE-2026-28684 (GHSA-mf9w-mj56-hr94), resides in the `set_key()` and `unset_key()` functions. These functions follow symbolic links when rewriting `.env` files, creating a...
The Lab · 2026-04-21 20:22:55 · GitHub Issues
A critical security vulnerability in the widely-used python-dotenv library exposes systems to local file overwrite attacks. The flaw, tracked as CVE-2026-28684 (GHSA-mf9w-mj56-hr94), resides in the `set_key()` and `unset_key()` functions. These functions follow symbolic links when rewriting `.env` files, creating a pat...
The Lab · 2026-04-21 22:22:57 · GitHub Issues
A critical vulnerability in the widely-used `python-dotenv` library exposes systems to arbitrary file overwrites. Tracked as CVE-2026-28684 (GHSA-mf9w-mj56-hr94), the flaw resides in the `set_key()` and `unset_key()` functions. These functions, responsible for modifying `.env` files that store sensitive configuration l...
The Lab · 2026-04-21 22:23:00 · GitHub Issues
A critical security vulnerability in the widely-used `python-dotenv` library has been patched, forcing a mandatory update for countless Python projects. The flaw, tracked as CVE-2026-28684, resides in the library's `set_key()` and `unset_key()` functions. These functions, used to modify `.env` files that store sensitiv...
The Lab · 2026-04-22 00:22:40 · GitHub Issues
A critical security flaw in the widely-used python-dotenv library has been patched, exposing projects to arbitrary file overwrite attacks. The vulnerability, tracked as CVE-2026-28684 (GHSA-mf9w-mj56-hr94), resides in the `set_key()` and `unset_key()` functions. These functions, responsible for modifying `.env` files c...
The Lab · 2026-04-22 00:22:41 · GitHub Issues
A critical security flaw in the widely-used python-dotenv library has been patched, exposing countless Python applications to potential local file system attacks. The vulnerability, tracked as CVE-2026-28684 (GHSA-mf9w-mj56-hr94), resides in the `set_key()` and `unset_key()` functions. These functions, used to modify `...
The Lab · 2026-04-22 02:22:44 · GitHub Issues
A critical security vulnerability in the widely-used python-dotenv library exposes systems to arbitrary file overwrite attacks. The flaw, tracked as CVE-2026-28684 (GHSA-mf9w-mj56-hr94), resides in the `set_key()` and `unset_key()` functions. These functions follow symbolic links when rewriting `.env` files, creating a...
The Lab · 2026-04-22 04:22:51 · GitHub Issues
A critical security flaw in the widely-used python-dotenv library exposes systems to arbitrary file overwrite attacks. The vulnerability, tracked as CVE-2026-28684 (GHSA-mf9w-mj56-hr94), stems from the library's `set_key()` and `unset_key()` functions following symbolic links when rewriting `.env` files. This design fl...