Skip to content

Low Security Vulnerability CVE-2026-1703 #684

@tglunde

Description

@tglunde

Summary

Please update pip to 26 in order to avoid this CVE

https://github.com/exasol/dbt-exasol/security/dependabot/61

Class/Type - path traversal vulnerability
Version(s) - pip <26
Severity - low
CVE Number - CVE-2026-1703

Details

Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

Impact

CVE low

References

https://github.com/exasol/dbt-exasol/security/dependabot/61

Solutions

Update to pip >=36

Credits

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity related change

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions