CVE-2026-47764

NameCVE-2026-47764
Descriptionpdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe _path_with_destdir() (which validates via Path.resolve() + is_relative_to()) with a bare os.path.join() that performs no path validation. A malicious wheel with traversal entries can write arbitrary files. This issue has been fixed in version 2.27.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pdm (PTS)bookworm2.2.1+ds1-1vulnerable
trixie2.20.1+ds1-2vulnerable
forky2.27.0-1fixed
sid2.28.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pdmsource(unstable)2.27.0-1

Notes

https://github.com/pdm-project/pdm/security/advisories/GHSA-78v8-vpjp-cjqh

Search for package or bug name: Reporting problems