Impact
This vulnerability allows an attacker to perform path traversal during wheel extraction on Windows systems, causing arbitrary files to be written outside the intended installation prefix. If the attacker can place an executable in a directory that is already on the user's PATH, the system may execute that file, leading to potential code execution. The weakness is categorized as CWE-22, indicating an insecure handling of filesystem paths.
Affected Systems
The issue affects the Astral-sh:uv package manager in versions 0.12.7 through 0.12.18, but only on Windows hosts; non‑Windows installations are not impacted.
Risk and Exploitability
The CVSS score is 5.9, which represents a moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to supply a malicious wheel, meaning the threat is local but could be remote if the wheel is fetched from an untrusted repository. Given the lack of an official workaround, upgrading to a fixed version is the most reliable mitigation.
OpenCVE Enrichment