VDB
KO

package

PyPI / uv

pkg:pypi/uv

LOW PyPI
GHSA-pjjw-68hj-v9mw

uv vulnerable to arbitrary file deletion through RECORD entries

Modified: 4/22/2026

MEDIUM PyPI crates.io
GHSA-4gg8-gxpx-9rph

uv is vulnerable to arbitrary file write through entry point names

Modified: 5/29/2026