pipenv is vulnerable to Exposure of Sensitive Information
30
Low Risk
Affected versions of this package may expose sensitive information in its package index authentication handling. Credentials embedded in [[source]] URLs within Pipfiles were passed directly to pip as -i and --extra-index-url command-line arguments, causing usernames, passwords, or tokens to be exposed through local process inspection interfaces such as ps, process listings, and /proc/<pid>/cmdline. A local attacker or co-located user on the same system could obtain private repository credentials and use them to access internal package indexes or other protected resources.
You are affected if you are using a version that falls within the vulnerable range.
pipenv is vulnerable to Exposure of Sensitive Information in versions 0.0.1 - 2026.5.2.
Upgrade the pipenv library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant