CVE-2026-1703

LOW

pip < 26.0 - Path Traversal via Maliciously Crafted Wheel Archive

Title source: llm
STIX 2.1

Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

Scores

CVSS v4 2.0
EPSS 0.0039
EPSS Percentile 30.6%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
pypi/pip 0 - 26.0PyPI
Python Packaging Authority/pip < 26.0
Published Feb 02, 2026
Tracked Since Feb 18, 2026