Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18. | |
| Title | uv: Path traversal on Windows through wheel extraction | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-02T16:00:53.033Z
Reserved: 2026-10-02T14:38:43.243Z
Link: CVE-2026-104843
Updated: 2026-10-02T16:00:13.161Z
Status : Received
Published: 2026-10-02T16:16:46.760
Modified: 2026-10-02T16:16:46.760
Link: CVE-2026-104843
No data.
OpenCVE Enrichment
Updated: 2026-10-02T16:30:14Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')