Логотип exploitDog
bind:CVE-2026-24049
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-24049

Количество 8

Количество 8

ubuntu логотип

CVE-2026-24049

18 дней назад

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-24049

18 дней назад

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-24049

18 дней назад

wheel is a command line tool for manipulating Python wheel files, as d ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20147-1

7 дней назад

Security update for python-wheel

EPSS: Низкий
github логотип

GHSA-8rrh-rw8j-w5fx

17 дней назад

Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack

CVSS3: 7.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-2090

4 дня назад

ELSA-2026-2090: python3.12-wheel security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1939

5 дней назад

ELSA-2026-1939: python3.12-wheel security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1902

4 дня назад

ELSA-2026-1902: python-wheel security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS3: 7.1
0%
Низкий
18 дней назад
nvd логотип
CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS3: 7.1
0%
Низкий
18 дней назад
debian логотип
CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as d ...

CVSS3: 7.1
0%
Низкий
18 дней назад
suse-cvrf логотип
openSUSE-SU-2026:20147-1

Security update for python-wheel

0%
Низкий
7 дней назад
github логотип
GHSA-8rrh-rw8j-w5fx

Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack

CVSS3: 7.1
0%
Низкий
17 дней назад
oracle-oval логотип
ELSA-2026-2090

ELSA-2026-2090: python3.12-wheel security update (IMPORTANT)

4 дня назад
oracle-oval логотип
ELSA-2026-1939

ELSA-2026-1939: python3.12-wheel security update (IMPORTANT)

5 дней назад
oracle-oval логотип
ELSA-2026-1902

ELSA-2026-1902: python-wheel security update (IMPORTANT)

4 дня назад

Уязвимостей на страницу