Address CVE-2026-28684: python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
envgap__pydantic__pydantic-settings-970
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
cd2084b7de6455d3f5cbf8b7d8426ebe8a2b04ba- Manifest
pyproject.toml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
pydantic/pydantic-settings #970 · read the original issue
Transient dependency python-dotenv has a CVE with a score of 6.6, pydantic-settings should bump python-dotenv requirement to at least 1.2.2, see also https://github.com/advisories/GHSA-mf9w-mj56-hr94 Found this as a project that requires pydantic-settings reported a transient dependency vulnerability in PyCharm IDE: <img width="950" height="241" alt="Image" src="https://github.com/user-attachments/assets/2d7fe56b-2904-4c31-b40d-c31ef8d4dad8" />
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]