LOW3.5
PYSEC-2026-2616
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Quick fix
PYSEC-2026-2616 — magic-wormhole: upgrade to the fixed version with the command below.
pip install --upgrade 'magic-wormhole>=0.24.0'Details
### Impact A receiver who specifies "--output <dir>" where that output directory currently exists (as a directory).
### Patches 0.24.0 will contain the patch
### Workarounds Ensure local target directories specified by "--output" do not already exist
### Resources Private email and Signal communications from a user. Magic Wormhole thanks @marduc812
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/magic-wormhole
Introduced in:
0.23.0Fixed in: 0.24.0Fix
pip install --upgrade 'magic-wormhole>=0.24.0'References
- https://github.com/magic-wormhole/magic-wormhole/security/advisories/GHSA-cf92-gfcw-6v53[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-42448[ADVISORY]
- https://github.com/magic-wormhole/magic-wormhole[PACKAGE]
- https://pypi.org/project/magic-wormhole[PACKAGE]
- https://github.com/advisories/GHSA-cf92-gfcw-6v53[ADVISORY]