Echo: python3.13: security update to 3.13.5-2+e24

medium Tenable Self-Hosted Container Security Plugin ID 463383

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the
VPATH variable is defined at build time and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python
assumes it is running in a source tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree. On Windows, since builds are written to
'PCbuild/', the value of VPATH is set to '..\..', which results in a landmark of
'..\..\Modules\setup.local'. This path is outside the install directory of Python, and may have different
permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib`
folder that will be discovered by an otherwise restricted install. Such a setup occurs with the legacy
default install location for all users (in the now superseded EXE installer), due to how Windows allows
all users to create folders in the root directory of their OS drive. Our recommended mitigation on Windows
is to migrate away from the legacy installer and use the new [Python install
manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs
where the directory two levels above the Python installation directory have equivalent permissions are
unaffected (in general, a per-user install cannot be modified at all by other users, removing any
escalation of privilege risk, and could be directly modified by a privileged user, making the potential
tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access
to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers -
earlier fixes are only provided as sources. Platforms other than Windows allow VPATH to be overridden, but
as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark
reference outside of the install directory. The landmark detection involving VPATH is a fallback for when
a more specific landmark - .\pybuilddir.txt - is absent, and was included for compatibility. Future
releases of Python will no longer include the fallback, and so builds will need to generate or preserve
the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since
3.11, and on other platforms for longer. (CVE-2026-12003)

Solution

Update the python3.13 library and its related packages to version 3.13.5-2+e24 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-12003

Plugin Details

Severity: Medium

ID: 463383

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.23

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-12003

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/18/2026

Vulnerability Publication Date: 6/16/2026

Reference Information

CVE: CVE-2026-12003