{"id":"CVE-2026-104843","title":"uv is a Python package and project manager written in Rust","summary":"uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-22"],"vendor":"astral-sh","product":"uv","affected":["uv >= 0.12.7, < 0.12.18"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T16:16:46.760","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104843","references":[{"url":"https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","label":"security-advisories@github.com"},{"url":"https://github.com/astral-sh/uv/pull/21923","label":"security-advisories@github.com"},{"url":"https://github.com/astral-sh/uv/releases/tag/0.12.18","label":"security-advisories@github.com"},{"url":"https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-02T15:57:14.347637Z"},"cvssSource":"cna","ingestedAt":"2026-10-02T16:22:59.526Z","slug":"CVE-2026-104843","body":"## Overview\n\nuv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}