Path traversal in pip - CVE-2026-1703

 

Path traversal in pip - CVE-2026-1703

Published: March 3, 2026


Vulnerability identifier: #VU123468
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-1703
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
pip
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
openSUSE Leap
openEuler
Anolis OS
DataStage on Cloud Pak for Data
python-pip
python3-pip
python-pip-help
python-pip-wheel
python311-pip
python3.10-pip

Detailed vulnerability description

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when installing and extracting wheel archives. A remote attacker can trick the victim into installing a malicious wheel archive and overwrite arbitrary files on the system. 


How to mitigate CVE-2026-1703

Install updates from vendor's website.

Sources