Path traversal in pip - CVE-2026-1703

 

Path traversal in pip - CVE-2026-1703

Published: March 3, 2026


Vulnerability identifier: #VU123468
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-1703
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when installing and extracting wheel archives. A remote attacker can trick the victim into installing a malicious wheel archive and overwrite arbitrary files on the system. 


Affected software

pip
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
openSUSE Leap
openEuler
Anolis OS
DataStage on Cloud Pak for Data
python-pip
python3-pip
python-pip-help
python-pip-wheel
python311-pip
python3.10-pip

How to mitigate CVE-2026-1703

Install updates from vendor's website.

pip - update to 26.0
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
python-pip - update to 10.0.1-13.17.1
python3-pip - update to 10.0.1-13.17.1
python-pip - addressed in versions 21.3.1-14, 23.3.1-9
python-pip-help - addressed in versions 21.3.1-14, 23.3.1-9
python-pip-wheel - addressed in versions 21.3.1-14, 23.3.1-9
python3-pip - addressed in versions 21.3.1-14, 23.3.1-9
python311-pip - update to 22.3.1-150400.17.19.1
python3.10-pip - update to 23.3.1-2
python3-pip - update to 23.3.1-6
python-pip-wheel - update to 23.3.1-6

External References

Related Security Bulletins