When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.
CVSS Details
- CVSS 4.0 Base Score: 2 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python3-pipUpgrade python2-pipUpgrade python-pip-wheel | May 20, 2026 | May 20, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 2, 2026 |
| Suse | — | Upgrade python-32bitUpgrade python-xmlUpgrade python-cursesUpgrade python-develUpgrade python-gdbmUpgrade python314-pipUpgrade python-pipUpgrade libpython2_7-1_0Upgrade python313-pipUpgrade python-demoUpgrade python313-pip-wheelUpgrade python311-pipUpgrade python-baseUpgrade python-idleUpgrade libpython2_7-1_0-32bitUpgrade python-doc-pdfUpgrade python-base-32bitUpgrade python3-pipUpgrade python-tkUpgrade pythonUpgrade python-doc | Feb 11, 2026 | Feb 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub