CVE-2026-1703Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-02); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-02: 2Mentions · 2026-02-17: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-02: 2Technical Details · 2026-02-17: 102-0202-17
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-022
Disclosure2
2026-02-171
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1703 When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to p… https://www.cve.org/CVERecord?id=CVE-2026-1703

    Post summary

    CVE-2026-1703 describes a path traversal issue when pip extracts malicious wheel archives, potentially allowing files to be written outside the intended directory. No exploit, patch, or active exploitation details are provided.

    00010232
    56.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Security Advisory: openSUSE Tumbleweed releases python311-pip 26.0.1-1.1 to patch CVE-2026-1703. CVSS 3.1 score of 3.1. While moderate, updating pip is crucial for #Python supply chain security. Read more: 👉 https://tinyurl.com/47vz9zy3 #Security https://t.co/hUu8QOiqCZ

    Post summary

    The advisory announces a patch for CVE‑2026‑1703, providing a CVSS score and emphasizing the importance of updating Python pip for supply chain security.

    0000055
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1703 Path Traversal in Pip Wheel Installation Allowing Unintended File Extraction https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1703

    Post summary

    The entry announces CVE-2026-1703, a path traversal flaw in pip wheel installation that may allow unintended file extraction, without providing details on patches, exploitation, or PoC.

    0000085
    4.0K followersView on X

Explore more