codesamplex

Sample

Prevent arbitrary file overwrite (CVE-2026-28684) by refusing symlink traversal by default in set_key and unset_key in python-dotenv 1.2.2, requiring follow_symlinks=True to modify link targets

sha256:33635aca120c0b15d09d8012282cd38192d4e12f28010a4847473b74123440ad

PUBLISHED L3_CONTRACT_PASS MIT-0

Case

Goal
Prevent arbitrary file overwrite (CVE-2026-28684) by refusing symlink traversal by default in set_key and unset_key in python-dotenv 1.2.2, requiring follow_symlinks=True to modify link targets HOW
Packages
python-dotenv 1.2.2
Environment
python
Created
2026-08-16T07:54:37Z

Contract

Files

Download the verified artifact (tar.gz) — the exact bytes the contract ran against

Origin Seeder

csx-seed

Verification receipts