CVE-2026-1703

low

Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

References

https://github.com/kriskimmerle/wheelaudit

https://mail.python.org/archives/list/[email protected]/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ/

https://github.com/pypa/pip/pull/13777

https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5106

Details

Source: Mitre, NVD

Published: 2026-02-02

Updated: 2026-04-15

Named Vulnerability: GHSA-6vgw-5pg2-w6jp

Risk Information

CVSS v2

Base Score: 3.2

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:N

Severity: Low

CVSS v3

Base Score: 3.9

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Severity: Low

CVSS v4

Base Score: 2

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Low

EPSS

EPSS: 0.00443