pdm has 4 CVEs on record between 2023 and 2026. 3 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 7.8 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2023-45805High· 7.8PDM Trojan Lockfile43CVE-2026-47781HighPDM is a Python package and dependency manager41CVE-2026-47764Highpdm is a Python package and dependency manager supporting the latest PEP standards41CVE-2026-47763Mediumpdm is a Python package and dependency manager supporting the latest PEP standards28
pdm vulnerabilities
CVEs affecting pdm, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-47763Mediumpdm is a Python package and dependency manager supporting the latest PEP standards
pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places t…
CVE-2026-47764Highpdm is a Python package and dependency manager supporting the latest PEP standards
pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overr…
CVE-2026-47781HighPDM is a Python package and dependency manager
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrust…
CVE-2023-45805High· 7.8PDM Trojan Lockfile
PDM Trojan Lockfile