GHSA-2cv4-cqwr-gwf7Medium

uv: Path traversal on Windows through wheel extraction

Published
October 5, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

In versions of uv from 0.12.7 to 0.12.18 on Windows, uv could be induced into writing a file outside of the installation prefix during wheel installation.

A malicious wheel could use this to place an executable outside of the intended environment, including in a directory already present on the user's PATH.

This vulnerability only affects Windows hosts; no other platforms are affected.

Patches

uv 0.12.18 and newer address this vulnerability. Users are encouraged to upgrade to 0.12.18.

Workarounds

There is no workaround other than upgrading to uv 0.12.18.

🎯 Affected products2

  • pip/uv:>= 0.12.7, < 0.12.18
  • rust/uv:>= 0.12.7, < 0.12.18

🔗 References (6)