CVE-2026-104843
uv: Path traversal on Windows through wheel extraction
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18.
| CWE | CWE-22 |
| Vendor | astral-sh |
| Product | uv |
| Published | Oct 2, 2026 |
| Last Updated | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for astral-sh uv
Be the first to know when new unknown vulnerabilities affecting astral-sh uv are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
astral-sh / uv
>= 0.12.7, < 0.12.18