magic-wormhole vulnerabilities
CVEs whose affected-version data names the magic-wormhole package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-42448Low· 3.5Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
▾ Sunlitmagic-wormhole · magic-wormholeEPSS 0.20%via OSV
CVE-2026-32116HighMagic Wormhole: "wormhole receive" allows arbitrary local file overwrite
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
▾ Twilightmagic-wormhole · magic-wormholeEPSS 0.35%via OSV