Input validation error in uv - CVE-2025-13327
Published: November 28, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input when handling .zip archives. A remote attacker can trick the victim into installing a package from a .zip archive and potentially execute arbitrary code by writing files to arbitrary locations.