#VU118846 Input validation error in uv
Published: November 28, 2025
uv
Astral
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input when handling .zip archives. A remote attacker can trick the victim into installing a package from a .zip archive and potentially execute arbitrary code by writing files to arbitrary locations.