CVE-2026-47781High▾ TwilightPDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrust…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is parsed. This happens because load_plugins() runs during Core.init() and adds .pdm-plugins via site.addsitedir(), which processes .pth files and immediately executes any line beginning with import, so the code runs with the privileges of the user invoking pdm and even a benign command such as pdm --version triggers it (making the impact strongest in CI, automation, and privileged contexts). The issue is fixed in version 2.27.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
pdm <= 2.26.9Patched in:
pdm 2.27.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47763Mediumpdm is a Python package and dependency manager supporting the latest PEP standards
CVE-2026-47764Highpdm is a Python package and dependency manager supporting the latest PEP standards
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2023-45805High· 7.8PDM Trojan Lockfile
CVE-2026-55522High· 7.8PraisonAI is a multi-agent teams system
CVE-2026-73073High· 7.3Vim is an open source, command line text editor