GHSA-2cv4-cqwr-gwf7Medium
uv: Path traversal on Windows through wheel extraction
🔗 CVE IDs covered (1)
📋 Description
Impact
In versions of uv from 0.12.7 to 0.12.18 on Windows, uv could be induced into writing a file outside of the installation prefix during wheel installation.
A malicious wheel could use this to place an executable outside of the intended environment, including in a directory already present on the user's PATH.
This vulnerability only affects Windows hosts; no other platforms are affected.
Patches
uv 0.12.18 and newer address this vulnerability. Users are encouraged to upgrade to 0.12.18.
Workarounds
There is no workaround other than upgrading to uv 0.12.18.
🎯 Affected products2
- pip/uv:>= 0.12.7, < 0.12.18
- rust/uv:>= 0.12.7, < 0.12.18
🔗 References (6)
- https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7
- https://nvd.nist.gov/vuln/detail/CVE-2026-104843
- https://github.com/astral-sh/uv/pull/21923
- https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b
- https://github.com/astral-sh/uv/releases/tag/0.12.18
- https://github.com/advisories/GHSA-2cv4-cqwr-gwf7