
CVE-2026-1703 When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to p… https://www.cve.org/CVERecord?id=CVE-2026-1703
Post summary
CVE-2026-1703 describes a path traversal issue when pip extracts malicious wheel archives, potentially allowing files to be written outside the intended directory. No exploit, patch, or active exploitation details are provided.


