CVE-2026-1703

Public on 2026-02-02
Modified on 2026-02-04
Description
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core python-pip Pending Fix
Amazon Linux 2023 python-pip Pending Fix
Amazon Linux 2 - Python3 Extra python3-pip No Fix Planned
Amazon Linux 2023 python3.11-pip Pending Fix
Amazon Linux 2023 python3.12-pip Pending Fix
Amazon Linux 2023 python3.13-pip Pending Fix
Amazon Linux 2 - Python3.8 Extra python38-pip No Fix Planned

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N