---
id: CVE-2026-47781
title: PDM is a Python package and dependency manager
summary: >-
  PDM is a Python package and dependency manager. In versions up to and
  including 2.26.9, PDM automatically loads project-local plugins from a
  .pdm-plugins directory during initialization, allowing an attacker-controlled
  file in an untrust…
severity: high
cwe:
  - CWE-94
  - CWE-829
vendor: pdm
product: pdm
affected:
  - pdm <= 2.26.9
patched:
  - pdm 2.27.0
published: '2026-08-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:51:43.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47781'
references:
  - url: 'https://github.com/pdm-project/pdm/releases/tag/2.27.0'
    label: security-advisories@github.com
  - url: 'https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf'
    label: security-advisories@github.com
  - url: 'https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/advisories/GHSA-qq6c-99pv-prvf'
tags:
  - nvd
  - ghsa
  - pip
epss: 0.00187
epssPercentile: 0.07359
aliases:
  - GHSA-qq6c-99pv-prvf
ecosystem: pip
ingestedAt: '2026-07-07T15:41:59.505Z'
---

## Overview

PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is parsed. This happens because load_plugins() runs during Core.init() and adds .pdm-plugins via site.addsitedir(), which processes .pth files and immediately executes any line beginning with import, so the code runs with the privileges of the user invoking pdm and even a benign command such as pdm --version triggers it (making the impact strongest in CI, automation, and privileged contexts). The issue is fixed in version 2.27.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-47781)

Affected packages:

- `pdm <= 2.26.9`

Patched in:

- `pdm 2.27.0`

Source: https://github.com/advisories/GHSA-qq6c-99pv-prvf
