Логотип exploitDog
bind:"GHSA-8rrh-rw8j-w5fx" OR bind:"CVE-2026-24049"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-8rrh-rw8j-w5fx" OR bind:"CVE-2026-24049"

Количество 8

Количество 8

github логотип

GHSA-8rrh-rw8j-w5fx

19 дней назад

Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2026-24049

19 дней назад

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-24049

19 дней назад

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-24049

19 дней назад

wheel is a command line tool for manipulating Python wheel files, as d ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20147-1

8 дней назад

Security update for python-wheel

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2090

6 дней назад

ELSA-2026-2090: python3.12-wheel security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1939

7 дней назад

ELSA-2026-1939: python3.12-wheel security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1902

6 дней назад

ELSA-2026-1902: python-wheel security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8rrh-rw8j-w5fx

Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack

CVSS3: 7.1
0%
Низкий
19 дней назад
ubuntu логотип
CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS3: 7.1
0%
Низкий
19 дней назад
nvd логотип
CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS3: 7.1
0%
Низкий
19 дней назад
debian логотип
CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as d ...

CVSS3: 7.1
0%
Низкий
19 дней назад
suse-cvrf логотип
openSUSE-SU-2026:20147-1

Security update for python-wheel

0%
Низкий
8 дней назад
oracle-oval логотип
ELSA-2026-2090

ELSA-2026-2090: python3.12-wheel security update (IMPORTANT)

6 дней назад
oracle-oval логотип
ELSA-2026-1939

ELSA-2026-1939: python3.12-wheel security update (IMPORTANT)

7 дней назад
oracle-oval логотип
ELSA-2026-1902

ELSA-2026-1902: python-wheel security update (IMPORTANT)

6 дней назад

Уязвимостей на страницу