-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Labels
securitySecurity related changeSecurity related change
Description
Summary
Please update pip to 26 in order to avoid this CVE
https://github.com/exasol/dbt-exasol/security/dependabot/61
| Class/Type | - path traversal vulnerability |
| Version(s) | - pip <26 |
| Severity | - low |
| CVE Number | - CVE-2026-1703 |
Details
Description
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.
Impact
CVE low
References
https://github.com/exasol/dbt-exasol/security/dependabot/61
Solutions
Update to pip >=36
Credits
Metadata
Metadata
Assignees
Labels
securitySecurity related changeSecurity related change