<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:03:38.438500+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-pdm-cve-2026-47764</id>
    <title>BREW-pdm-CVE-2026-47764 — pdm: Path traversal in wheel installation via overridden write_to_fs</title>
    <updated>2026-10-03T19:03:38.440797+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: pdm</p>
<p>pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe _path_with_destdir() (which validates via Path.resolve() + is_relative_to()) with a bare os.path.join() that performs no path validation. A malicious wheel with traversal entries can write arbitrary files. This issue has been fixed in version 2.27.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-pdm-cve-2026-47764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-47764</id>
    <title>CVE-2026-47764 — pdm: Path traversal in wheel installation via overridden write_to_fs</title>
    <updated>2026-10-03T19:03:38.440846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> pdm-project pdm</p>
<p>pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe _path_with_destdir() (which validates via Path.resolve() + is_relative_to()) with a bare os.path.join() that performs no path validation. A malicious wheel with traversal entries can write arbitrary files. This issue has been fixed in version 2.27.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-47764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-78v8-vpjp-cjqh</id>
    <title>GHSA-78v8-vpjp-cjqh — PDM  wheel installation leads to Path Traversal via overridden write_to_fs</title>
    <updated>2026-10-03T19:03:38.440876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pdm</p>
<p>InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe _path_with_destdir() (which validates via Path.resolve() + is_relative_to()) with a bare os.path.join() that performs no path validation. A malicious wheel with traversal entries can write arbitrary files. Same class as Poetry CVE-2026-34591. Fix ready at: https://github.com/pdm-project/pdm/pull/3787.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-78v8-vpjp-cjqh"/>
  </entry>
</feed>
