Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
Exploitability
AV:LAC:MAu:NImpact
C:CI:CA:C6.9/AV:L/AC:M/Au:N/C:C/I:C/A:C