---
schema_version: '1.0'
id: security-20260711-23efcc
url: https://osv.dev/vulnerability/PYSEC-2026-1796
url_hash: 23efcca822c206efb6d345303d724a4424cf7be0448cf7de30be7ed27156b58f
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-1796
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-1703
- PYSEC-2026-1796
- severity:CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- pip
- PyPI
lang: en
published_at: '2026-07-07T16:36:56Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-11T06:39:54Z'
status: published
content_hash: 3d7237195eb5eaf88473a44a6753f43296bbdf00f63e256ee0b00cddac16980b
license_note: full
summary: pip Path Traversal vulnerability
summary_source: rss
summary_en: pip Path Traversal vulnerability
entities:
- name: PyTerrier retrieval pipelines
  type: data
- name: XPath Agent
  type: artifact
key_facts: []
related: []
related_auto:
- name: QueryExplorer
  type: system
  weight: 1.0
- name: Agent Openclaw
  type: person
  weight: 1.0
title: 'CVE-2026-1703: pip Path Traversal vulnerability'
---

# CVE-2026-1703: pip Path Traversal vulnerability

## TL;DR
pip Path Traversal vulnerability

## Key Points
- cve / CVE-2026-1703 / PYSEC-2026-1796 / severity:CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N / pip / PyPI

## Details
**Severity:** CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
**Advisory:** PYSEC-2026-1796 (CVE-2026-1703)

**Affected (your watchlist):**
- `PyPI:pip` 24.0 → fixed in 26.0 [docker/docker-portal+docker/local+docker/mac]
- `PyPI:pip` 25.0.1 → fixed in 26.0 [docker/docker-graphrag+docker/docker-llmwiki+docker/docker-portal+docker/docker-strands+docker/local+docker/mac]
- `PyPI:pip` 25.1.1 → fixed in 26.0 [docker/docker-mcp]

**Details:**
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

**References:**
- https://nvd.nist.gov/vuln/detail/CVE-2026-1703
- https://github.com/pypa/pip/pull/13777
- https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735
- https://github.com/pypa/pip
- https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ
- https://pypi.org/project/pip
- https://github.com/advisories/GHSA-6vgw-5pg2-w6jp

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-1796_

## Source
元記事: [CVE-2026-1703: pip Path Traversal vulnerability](https://osv.dev/vulnerability/PYSEC-2026-1796) — published 2026-07-07T16:36:56Z
