pdm vulnerabilities
CVEs whose affected-version data names the pdm package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-47763Mediumpdm is a Python package and dependency manager supporting the latest PEP standards
pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places t…
CVE-2026-47764Highpdm is a Python package and dependency manager supporting the latest PEP standards
pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overr…
CVE-2026-47781HighPDM is a Python package and dependency manager
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrust…
CVE-2023-45805High· 7.8PDM Trojan Lockfile
PDM Trojan Lockfile