Path traversal in pip - CVE-2026-1703
Published: March 3, 2026
Vulnerability identifier: #VU123468
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-1703
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when installing and extracting wheel archives. A remote attacker can trick the victim into installing a malicious wheel archive and overwrite arbitrary files on the system.
Affected software
pip
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
openSUSE Leap
openEuler
Anolis OS
DataStage on Cloud Pak for Data
python-pip
python3-pip
python-pip-help
python-pip-wheel
python311-pip
python3.10-pip
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
openSUSE Leap
openEuler
Anolis OS
DataStage on Cloud Pak for Data
python-pip
python3-pip
python-pip-help
python-pip-wheel
python311-pip
python3.10-pip
How to mitigate CVE-2026-1703
Install updates from vendor's website.
pip - update to 26.0
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
python-pip - update to 10.0.1-13.17.1
python3-pip - update to 10.0.1-13.17.1
python-pip - addressed in versions 21.3.1-14, 23.3.1-9
python-pip-help - addressed in versions 21.3.1-14, 23.3.1-9
python-pip-wheel - addressed in versions 21.3.1-14, 23.3.1-9
python3-pip - addressed in versions 21.3.1-14, 23.3.1-9
python311-pip - update to 22.3.1-150400.17.19.1
python3.10-pip - update to 23.3.1-2
python3-pip - update to 23.3.1-6
python-pip-wheel - update to 23.3.1-6
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
python-pip - update to 10.0.1-13.17.1
python3-pip - update to 10.0.1-13.17.1
python-pip - addressed in versions 21.3.1-14, 23.3.1-9
python-pip-help - addressed in versions 21.3.1-14, 23.3.1-9
python-pip-wheel - addressed in versions 21.3.1-14, 23.3.1-9
python3-pip - addressed in versions 21.3.1-14, 23.3.1-9
python311-pip - update to 22.3.1-150400.17.19.1
python3.10-pip - update to 23.3.1-2
python3-pip - update to 23.3.1-6
python-pip-wheel - update to 23.3.1-6
External References
Related Security Bulletins
- Path traversal in Python pip
- openEuler 24.03 LTS SP1 update for python-pip
- openEuler 24.03 LTS update for python-pip
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 24.03 LTS SP3 update for python-pip
- openEuler 24.03 LTS SP2 update for python-pip
- SUSE update for python-pip
- SUSE update for python-pip
- Anolis OS update for python3.10-pip
- Anolis OS update for python-pip
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data