NONE · 0

CVE-2026-104843

uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation...

Vulnerability Description

uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-104843?

CVE-2026-104843 is a documented vulnerability. uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation...

How severe is CVE-2026-104843?

CVSS scoring is not yet available for CVE-2026-104843. Check NVD for updates.

Is there a patch for CVE-2026-104843?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.