Vulnerability GHSA-2cv4-cqwr-gwf7

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
October 05, 2026 at 11:42 PM UTC
uv: Path traversal on Windows through wheel extraction
0.12.7 - 0.12.17
0.12.7 - 0.12.17

Summary

uv: Path traversal on Windows through wheel extraction

Details

Impact

In versions of uv from 0.12.7 to 0.12.18 on Windows, uv could be induced into writing a file outside of the installation prefix during wheel installation.

A malicious wheel could use this to place an executable outside of the intended environment, including in a directory already present on the user's PATH.

This vulnerability only affects Windows hosts; no other platforms are affected.

Patches

uv 0.12.18 and newer address this vulnerability. Users are encouraged to upgrade to 0.12.18.

Workarounds

There is no workaround other than upgrading to uv 0.12.18.

Impacted packages

Timeline

Published
7 hours ago
October 05, 2026 at 11:42 PM UTC
Fixed (0.12.18)
13 days ago
September 22, 2026 at 10:58 PM UTC
Fixed (0.12.18)
13 days ago
September 22, 2026 at 11:01 PM UTC
Last Modified
7 hours ago
October 06, 2026 at 12:00 AM UTC