wheel is vulnerable to Path Traversal
55
Medium Risk
The wheel convert command builds the output wheel path from the project name and version read from the input archive. Converting an archive whose name or version contains path separators can therefore write the produced wheel to an arbitrary location outside the destination directory, allowing files chosen by the archive contents to be created or overwritten. The fix rejects converted output paths that resolve outside the requested destination directory.
You are affected if you are using a version that falls within the vulnerable range and you run wheel convert on an .egg or wininst archive whose project name or version metadata comes from an untrusted source.
wheel is vulnerable to Path Traversal in versions 0.9.6 - 0.47.0.
Upgrade the wheel library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant