NONE · 0

CVE-2026-1703

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation dire...

Vulnerability Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-1703?

CVE-2026-1703 is a documented vulnerability. When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation dire...

How severe is CVE-2026-1703?

CVSS scoring is not yet available for CVE-2026-1703. Check NVD for updates.

Is there a patch for CVE-2026-1703?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.