#VU125721 Path traversal in uv
Published: April 9, 2026
uv
Astral
Description
The vulnerability allows a remote attacker to write files outside the intended installation prefix.
The vulnerability exists due to path traversal in tar extraction when processing a specially crafted source distribution with a sequence of symlinks. A remote attacker can provide a specially crafted source distribution to write files outside the intended installation prefix.
Only source distribution installations are affected; wheel installations are not affected.