{"id":"GHSA-2cv4-cqwr-gwf7","summary":"uv: Path traversal on Windows through wheel extraction","details":"### Impact\n\nIn versions of uv from 0.12.7 to 0.12.18 on Windows, uv could be induced into writing a file outside of the installation prefix during wheel installation.\n\nA malicious wheel could use this to place an executable outside of the intended environment, including in a directory already present on the user's PATH. \n\nThis vulnerability only affects Windows hosts; no other platforms are affected.\n\n### Patches\n\nuv 0.12.18 and newer address this vulnerability. Users are encouraged to upgrade to 0.12.18.\n\n### Workarounds\n\nThere is no workaround other than upgrading to uv 0.12.18.","aliases":["CVE-2026-104843"],"modified":"2026-10-06T00:00:10.468182515Z","published":"2026-10-05T23:42:09Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-05T23:42:09Z","nvd_published_at":"2026-10-02T16:16:46Z","cwe_ids":["CWE-22"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104843"},{"type":"WEB","url":"https://github.com/astral-sh/uv/pull/21923"},{"type":"WEB","url":"https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b"},{"type":"PACKAGE","url":"https://github.com/astral-sh/uv"},{"type":"WEB","url":"https://github.com/astral-sh/uv/releases/tag/0.12.18"}],"affected":[{"package":{"name":"uv","ecosystem":"PyPI","purl":"pkg:pypi/uv"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.12.7"},{"fixed":"0.12.18"}]}],"versions":["0.12.10","0.12.11","0.12.12","0.12.13","0.12.14","0.12.15","0.12.16","0.12.17","0.12.7","0.12.8","0.12.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-2cv4-cqwr-gwf7/GHSA-2cv4-cqwr-gwf7.json"}},{"package":{"name":"uv","ecosystem":"crates.io","purl":"pkg:cargo/uv"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.12.7"},{"fixed":"0.12.18"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-2cv4-cqwr-gwf7/GHSA-2cv4-cqwr-gwf7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}