← All tasks
pythonpydantic/pydantic-settings #970Not a task: already works

Address CVE-2026-28684: python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback

envgap__pydantic__pydantic-settings-970

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
cd2084b7de6455d3f5cbf8b7d8426ebe8a2b04ba
Manifest
pyproject.toml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

pydantic/pydantic-settings #970 · read the original issue
Transient dependency python-dotenv has a CVE with a score of 6.6, pydantic-settings should bump python-dotenv requirement to at least 1.2.2, see also https://github.com/advisories/GHSA-mf9w-mj56-hr94

Found this as a project that requires pydantic-settings reported a transient dependency vulnerability in PyCharm IDE:

<img width="950" height="241" alt="Image" src="https://github.com/user-attachments/assets/2d7fe56b-2904-4c31-b40d-c31ef8d4dad8" />
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]