Root has patched CVE-2026-28684 in the rootio-python-dotenv package for Root:PyPI. Multiple fixed versions available.
{ "source": "Root", "severity": "MEDIUM", "distro": "pypi", "distro_version": "" }
"https://api.root.io/external/osv/ROOT-APP-PYPI-CVE-2026-28684.json"
true
"root.io.2"
4.0
"1.1.1"
[ "1.2.1+root.io.1", "1.1.1+root.io.1", "1.2.1+root.io.2", "1.1.1+root.io.2" ]
"1.1.1+aikido.2"
2.0
""
[ "1.2.1+aikido.2", "1.1.1+aikido.2" ]