Path traversal in uv - #VU125721
Published: April 9, 2026
uv
Detailed vulnerability description
The vulnerability allows a remote attacker to write files outside the intended installation prefix.
The vulnerability exists due to path traversal in tar extraction when processing a specially crafted source distribution with a sequence of symlinks. A remote attacker can provide a specially crafted source distribution to write files outside the intended installation prefix.
Only source distribution installations are affected; wheel installations are not affected.