CVE-2026-1703

LOW

Pypi Pip < 26.0 - Path Traversal

Title source: rule
STIX 2.1

Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

Scores

CVSS v4 2.0
EPSS 0.0003
EPSS Percentile 7.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
pypi/pip 0 - 26.0PyPI
Python Packaging Authority/pip < 26.0
Published Feb 02, 2026
Tracked Since Feb 18, 2026