---
schema_version: '1.0'
id: security-20260711-23941b
url: https://osv.dev/vulnerability/GHSA-6vgw-5pg2-w6jp
url_hash: 23941bc1a7e2a94b9dd4f42172ed9cf6b7a16be4d0bf1a9c7b44d8e07988876f
canonical_url: https://osv.dev/vulnerability/GHSA-6vgw-5pg2-w6jp
source: osv:ghsa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-1703
- GHSA-6vgw-5pg2-w6jp
- severity:CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- pip
- PyPI
lang: en
published_at: '2026-02-02T15:30:34Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-11T06:39:54Z'
status: published
content_hash: f77c18f160db37bdd88a8a75928fd2446f8802dc33b1298cd9d8ed89573e2b2e
license_note: full
summary: pip Path Traversal vulnerability
summary_source: rss
summary_en: pip Path Traversal vulnerability
entities:
- name: PyTerrier retrieval pipelines
  type: data
- name: XPath Agent
  type: artifact
key_facts: []
related: []
related_auto:
- name: QueryExplorer
  type: system
  weight: 1.0
- name: Agent Openclaw
  type: person
  weight: 1.0
title: 'CVE-2026-1703: pip Path Traversal vulnerability'
---

# CVE-2026-1703: pip Path Traversal vulnerability

## TL;DR
pip Path Traversal vulnerability

## Key Points
- cve / CVE-2026-1703 / GHSA-6vgw-5pg2-w6jp / severity:CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N / pip / PyPI

## Details
**Severity:** CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
**Advisory:** GHSA-6vgw-5pg2-w6jp (CVE-2026-1703)

**Affected (your watchlist):**
- `PyPI:pip` 24.0 → fixed in 26.0 [docker/docker-portal+docker/local+docker/mac]
- `PyPI:pip` 25.0.1 → fixed in 26.0 [docker/docker-graphrag+docker/docker-llmwiki+docker/docker-portal+docker/docker-strands+docker/local+docker/mac]
- `PyPI:pip` 25.1.1 → fixed in 26.0 [docker/docker-mcp]

**Details:**
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

**References:**
- https://nvd.nist.gov/vuln/detail/CVE-2026-1703
- https://github.com/pypa/pip/pull/13777
- https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735
- https://github.com/pypa/pip
- https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ

_Data: OSV.dev (upstream: ghsa) — https://osv.dev/vulnerability/GHSA-6vgw-5pg2-w6jp_

## Source
元記事: [CVE-2026-1703: pip Path Traversal vulnerability](https://osv.dev/vulnerability/GHSA-6vgw-5pg2-w6jp) — published 2026-02-02T15:30:34Z
