CVE Database
/

CVE-2026-1703

Back to search

CVE-2026-1703

Published: Feb 2, 2026

Modified: Feb 2, 2026

PUBLISHED

Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

VendorProductVersions

Python Packaging Authority

pip

affected
0 - < 26.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now