CVE-2026-1703
ADVISORY - githubSummary
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.
Common Weakness Enumeration (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
NIST
-
CVSS SCORE
2lowGitHub
-
CVSS SCORE
2lowDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AlowAmazon
-
CVSS SCORE
N/AlowAmazon
-
CVSS SCORE
N/AlowBitnami
BIT-pip-2026-1703
-
CVSS SCORE
2lowRed Hat
1.3
CVSS SCORE
3.9lowChainguard
CGA-j3wx-hhh2-pqmx
-
minimos
MINI-7hhq-w9p3-cxv4
-
minimos
MINI-7mh7-c68w-24x8
-
minimos
MINI-c44g-5vx9-42rg
-
minimos
MINI-pc6q-j833-4c2j
-
minimos
MINI-pcx8-f4wp-6938
-
minimos
MINI-phq9-h939-7q2g
-