distlib is vulnerable to Path Traversal
59
Medium Risk
Affected versions of this library do not consistently confine wheel installation, extension mounting, package resource lookups, and tar symlink targets to their intended directories when processing crafted archive or path input. A hostile simple-index response can also inflate without bound during decompression and exhaust memory. Before the fix, these gaps allowed files to be written or read outside intended install, cache, or package bases and could enable denial-of-service during index scraping. The patch adds path containment checks across wheel, resource, and unarchive flows and caps decompressed index size.
You are affected if you are using a version that falls within the vulnerable range.
distlib is vulnerable to Path Traversal in versions 0.1.0 - 0.4.1.
Upgrade the distlib library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant