VDB
Sign up

package

PyPI/uv

pkg:pypi/uv

MEDIUMPyPIcrates.io
GHSA-4gg8-gxpx-9rph

uv is vulnerable to arbitrary file write through entry point names

Modified: 5/29/2026

LOWPyPI
GHSA-pjjw-68hj-v9mw

uv vulnerable to arbitrary file deletion through RECORD entries

Modified: 9/10/2026

LOWPyPI
GHSA-w476-p2h3-79g9

uv has differential in tar extraction with PAX headers

Modified: 2/4/2026