Reliance on Untrusted Inputs in a Security Decision in pyinstaller - #VU144255
Published: August 19, 2026
Vulnerability details
The vulnerability allows a local user to remove protected resources.
The vulnerability exists due to reliance on untrusted inputs in a security decision in the PyInstaller onefile bootloader on POSIX systems when inheriting spoofed _PYI_ environment variables. A local user can manipulate environment variables to remove protected resources.
This issue affects onefile executables on POSIX systems and requires the ability to execute a privileged PyInstaller-built executable.