CVE-2026-13346: pip absolute path traversal during download from malicious package indexes

Published Jul 29, 2026
·
Updated

pip absolute path traversal during download from malicious package indexes

Other sources

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.

This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running pip download with the --only-binary option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.

NVD

Affected Software

4 affected componentsFixes available
pip
Microsoft azl3 python-pip 24.2-9<24.2-10
24.2-10
Microsoft azl3 python-virtualenv 20.36.1-5<20.36.1-6
20.36.1-6
pypa pip<26.2

Remediation

Event History

Jul 29, 2026
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 7, 2026
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-13346?

CVE-2026-13346 has a medium severity rating of 5.6 according to the CVSS scoring.

2

How does CVE-2026-13346 affect pip users?

CVE-2026-13346 allows pip to incorrectly handle doubly-encoded package URLs, potentially leading to the installation of files in arbitrary locations on disk.

3

What are the requirements for exploiting CVE-2026-13346?

To exploit CVE-2026-13346, an attacker must host a malicious package index and the user must download or install a package from that index.

4

How can I mitigate the risk posed by CVE-2026-13346?

To mitigate CVE-2026-13346, avoid installing packages from untrusted or unknown package indexes.

5

When was CVE-2026-13346 published?

CVE-2026-13346 was published on July 29, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203