Intel

AIKIDO-2026-658385

python-discovery is vulnerable to Uncontrolled Search Path Element

Uncontrolled Search Path ElementGHSA-f7q5-7cq5-gvgh Published 5 days ago

69

Medium Risk

This Affects:

PYTHONpython-discovery
0.0.1 - 1.6.0
Fixed in 1.6.1
Are you affected? Scan for Free

TL;DR

python-discovery's get_paths() turns every PATH entry into a Path without filtering empty components. A leading, trailing, or doubled path separator produces an empty entry that resolves to the current working directory, so discovery's interrogation step searches and executes whatever binary sits there. An attacker who can write a file such as python3.11 into that directory gets it executed as a candidate interpreter, whether or not discovery ultimately selects it as the result. The fix filters out empty PATH components before they become search candidates.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your PATH environment variable contains an empty entry while discovery runs from a directory that untrusted content can write to.

Background info

python-discovery is vulnerable to Uncontrolled Search Path Element in versions 0.0.1 - 1.6.0.

How to fix this

Upgrade the python-discovery library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform