In versions of uv from 0.12.7 to 0.12.18 on Windows, uv could be induced into writing a file outside of the installation prefix during wheel installation.
A malicious wheel could use this to place an executable outside of the intended environment, including in a directory already present on the user's PATH.
This vulnerability only affects Windows hosts; no other platforms are affected.
uv 0.12.18 and newer address this vulnerability. Users are encouraged to upgrade to 0.12.18.
There is no workaround other than upgrading to uv 0.12.18.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-05T23:42:09Z",
"nvd_published_at": "2026-10-02T16:16:46Z",
"severity": "MODERATE"
}