Launch Week Day 1: Announcing Security Design Review
UNKNOWN PyPI

pip Path Traversal vulnerability

GHSA-6vgw-5pg2-w6jp · CVE-2026-1703

Published · Modified

Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

Ready to move

Start Securing

Free, no credit card | First findings in minutes