๐Ÿ” CVE Alert

CVE-2026-104843

UNKNOWN 0.0

uv: Path traversal on Windows through wheel extraction

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18.

CWE CWE-22
Vendor astral-sh
Product uv
Published Oct 2, 2026
Last Updated Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for astral-sh uv

Be the first to know when new unknown vulnerabilities affecting astral-sh uv are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

astral-sh / uv
>= 0.12.7, < 0.12.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7 github.com: https://github.com/astral-sh/uv/pull/21923 github.com: https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b github.com: https://github.com/astral-sh/uv/releases/tag/0.12.18