{"id":"CVE-2026-13346","summary":"pip absolute path traversal during download from malicious package indexes","details":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.","modified":"2026-08-12T10:57:06.938017784Z","published":"2026-07-29T18:33:50.820Z","related":["SUSE-SU-2026:3588-1","SUSE-SU-2026:3589-1","openSUSE-SU-2026:11451-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13346.json","cna_assigner":"PSF","cwe_ids":["CWE-36"]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/29/7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13346.json"},{"type":"ADVISORY","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13346"},{"type":"FIX","url":"https://github.com/pypa/pip/pull/14110"},{"type":"PACKAGE","url":"https://github.com/pypa/pip"},{"type":"PACKAGE","url":"https://pypi.org/project/pip"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pypa/pip","events":[{"introduced":"0"},{"fixed":"4b6ae5c4d7d63a61a99fbecbead8dbc35cc8b357"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"26.2"}]}}],"versions":["26.0","21.3","21.0","20.0.2","19.1.1","19.0.2","19.0","18.1","18.0","10.0.1","10.0.0","9.0.1","9.0.0","6.0","1.4rc2","1.4rc1","1.2","1.0","0.8.3","0.8.2","0.8","0.7.1","0.7","0.6","0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13346.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}