HIGH7.8
PYSEC-2026-1968
TkEasyGUI Affected by Uncontrolled Search Path Element Issue
Quick fix
PYSEC-2026-1968 — tkeasygui: upgrade to the fixed version with the command below.
pip install --upgrade 'tkeasygui>=1.0.22'Details
Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege of running the program.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-55671[ADVISORY]
- https://github.com/kujirahand/tkeasygui-python[PACKAGE]
- https://github.com/kujirahand/tkeasygui-python/releases/tag/v1.0.22[WEB]
- https://jvn.jp/en/jp/JVN48739895[WEB]
- https://pypi.org/project/tkeasygui[PACKAGE]
- https://github.com/advisories/GHSA-ph2w-cx28-vhrq[ADVISORY]