CVE-2026-1703

Published: February 3, 2026Last modified: June 3, 2026

Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpy3-pipFixed (22.3.1-r5)
25 LTSpy3-pipFixed (25.1.1-r2)
Streampy3-pipFixed (26.0-r1)
Hardened Containers23 LTSpy3-pipFixed (22.3.1-r5)
25 LTSpy3-pipFixed (25.1.1-r2)
Streampy3-pipFixed (26.0-r1)

References

ON THIS PAGE