<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:54:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:10407 — Moderate: python-setuptools security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:10407</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-setuptools, AlmaLinux:9: python3-setuptools-wheel&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* setuptools: Path Traversal Vulnerability in setuptools PackageIndex (CVE-2025-47273)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-setuptools, AlmaLinux:9: python3-setuptools-wheel&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* setuptools: Path Traversal Vulnerability in setuptools PackageIndex (CVE-2025-47273)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:10407</guid>
    </item>
    <item>
      <title>bdu:2025-08604</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08604</link>
      <description>bdu:2025-08604</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08604</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-47273</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-47273</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-setuptools, Alpaquita:stream: py3-setuptools, BellSoft Hardened Containers:23: py3-setuptools, BellSoft Hardened Containers:stream: py3-setuptools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-setuptools, Alpaquita:stream: py3-setuptools, BellSoft Hardened Containers:23: py3-setuptools, BellSoft Hardened Containers:stream: py3-setuptools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-47273</guid>
    </item>
    <item>
      <title>BIT-setuptools-2025-47273 — setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write</title>
      <link>https://cve.radiocsirt.org/vuln/bit-setuptools-2025-47273</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: setuptools&lt;/p&gt;
&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: setuptools&lt;/p&gt;
&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-setuptools-2025-47273</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2025-47273 — setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2025-47273</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;### Summary 
A path traversal vulnerability in `PackageIndex` was fixed in setuptools version 78.1.1&lt;/p&gt;
&lt;p&gt;### Details
```
    def _download_url(self, url, tmpdir):
        # Determine download filename
        #
        name, _fragment = egg_info_for_url(url)
        if name:
            while &amp;#39;..&amp;#39; in name:
                name = name.replace(&amp;#39;..&amp;#39;, &amp;#39;.&amp;#39;).replace(&amp;#39;\\&amp;#39;, &amp;#39;_&amp;#39;)
        else:
            name = &amp;#34;__downloaded__&amp;#34;  # default if URL has no path contents&lt;/p&gt;
&lt;p&gt;if name.endswith(&amp;#39;.[egg.zip](http://egg.zip/)&amp;#39;):
            name = name[:-4]  # strip the extra .zip before download&lt;/p&gt;
&lt;p&gt;--&amp;gt;       filename = os.path.join(tmpdir, name)
```&lt;/p&gt;
&lt;p&gt;Here: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88&lt;/p&gt;
&lt;p&gt;`os.path.join()` discards the first argument `tmpdir` if the second begins with a slash or drive letter.
`name` is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of &amp;#39;..&amp;#39; with &amp;#39;.&amp;#39;, it is insufficient.&lt;/p&gt;
&lt;p&gt;### Risk Assessment
As easy_install and package_index are deprecated, the exploitation surface is reduced.
However, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.&lt;/p&gt;
&lt;p&gt;### Impact
An attacker would be allowed to write files to arbitrary locations on th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;### Summary 
A path traversal vulnerability in `PackageIndex` was fixed in setuptools version 78.1.1&lt;/p&gt;
&lt;p&gt;### Details
```
    def _download_url(self, url, tmpdir):
        # Determine download filename
        #
        name, _fragment = egg_info_for_url(url)
        if name:
            while &amp;#39;..&amp;#39; in name:
                name = name.replace(&amp;#39;..&amp;#39;, &amp;#39;.&amp;#39;).replace(&amp;#39;\\&amp;#39;, &amp;#39;_&amp;#39;)
        else:
            name = &amp;#34;__downloaded__&amp;#34;  # default if URL has no path contents&lt;/p&gt;
&lt;p&gt;if name.endswith(&amp;#39;.[egg.zip](http://egg.zip/)&amp;#39;):
            name = name[:-4]  # strip the extra .zip before download&lt;/p&gt;
&lt;p&gt;--&amp;gt;       filename = os.path.join(tmpdir, name)
```&lt;/p&gt;
&lt;p&gt;Here: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88&lt;/p&gt;
&lt;p&gt;`os.path.join()` discards the first argument `tmpdir` if the second begins with a slash or drive letter.
`name` is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of &amp;#39;..&amp;#39; with &amp;#39;.&amp;#39;, it is insufficient.&lt;/p&gt;
&lt;p&gt;### Risk Assessment
As easy_install and package_index are deprecated, the exploitation surface is reduced.
However, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.&lt;/p&gt;
&lt;p&gt;### Impact
An attacker would be allowed to write files to arbitrary locations on th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2025-47273</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0693 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0693</link>
      <description>certfr-2025-avi-0693</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0693</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EQ71754 — Security fixes for CVE-2024-6345, CVE-2025-47273, CVE-2025-59375 applied in versions: 3.11.14-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-eq71754</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: python3&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the python3 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: python3&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the python3 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-eq71754</guid>
    </item>
    <item>
      <title>EUVD-2026-241546</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-241546</link>
      <description>EUVD-2026-241546</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-241546</guid>
    </item>
    <item>
      <title>fkie_cve-2025-47273</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-47273</link>
      <description>&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-47273</guid>
    </item>
    <item>
      <title>GHSA-5rjg-fvgr-3xxf — setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5rjg-fvgr-3xxf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: setuptools&lt;/p&gt;
&lt;p&gt;### Summary 
A path traversal vulnerability in `PackageIndex` was fixed in setuptools version 78.1.1&lt;/p&gt;
&lt;p&gt;### Details
```
    def _download_url(self, url, tmpdir):
        # Determine download filename
        #
        name, _fragment = egg_info_for_url(url)
        if name:
            while &amp;#39;..&amp;#39; in name:
                name = name.replace(&amp;#39;..&amp;#39;, &amp;#39;.&amp;#39;).replace(&amp;#39;\\&amp;#39;, &amp;#39;_&amp;#39;)
        else:
            name = &amp;#34;__downloaded__&amp;#34;  # default if URL has no path contents&lt;/p&gt;
&lt;p&gt;if name.endswith(&amp;#39;.[egg.zip](http://egg.zip/)&amp;#39;):
            name = name[:-4]  # strip the extra .zip before download&lt;/p&gt;
&lt;p&gt;--&amp;gt;       filename = os.path.join(tmpdir, name)
```&lt;/p&gt;
&lt;p&gt;Here: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88&lt;/p&gt;
&lt;p&gt;`os.path.join()` discards the first argument `tmpdir` if the second begins with a slash or drive letter.
`name` is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of &amp;#39;..&amp;#39; with &amp;#39;.&amp;#39;, it is insufficient.&lt;/p&gt;
&lt;p&gt;### Risk Assessment
As easy_install and package_index are deprecated, the exploitation surface is reduced.
However, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.&lt;/p&gt;
&lt;p&gt;### Impact
An attacker would be allowed to write files to arbitrary locations on th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: setuptools&lt;/p&gt;
&lt;p&gt;### Summary 
A path traversal vulnerability in `PackageIndex` was fixed in setuptools version 78.1.1&lt;/p&gt;
&lt;p&gt;### Details
```
    def _download_url(self, url, tmpdir):
        # Determine download filename
        #
        name, _fragment = egg_info_for_url(url)
        if name:
            while &amp;#39;..&amp;#39; in name:
                name = name.replace(&amp;#39;..&amp;#39;, &amp;#39;.&amp;#39;).replace(&amp;#39;\\&amp;#39;, &amp;#39;_&amp;#39;)
        else:
            name = &amp;#34;__downloaded__&amp;#34;  # default if URL has no path contents&lt;/p&gt;
&lt;p&gt;if name.endswith(&amp;#39;.[egg.zip](http://egg.zip/)&amp;#39;):
            name = name[:-4]  # strip the extra .zip before download&lt;/p&gt;
&lt;p&gt;--&amp;gt;       filename = os.path.join(tmpdir, name)
```&lt;/p&gt;
&lt;p&gt;Here: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88&lt;/p&gt;
&lt;p&gt;`os.path.join()` discards the first argument `tmpdir` if the second begins with a slash or drive letter.
`name` is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of &amp;#39;..&amp;#39; with &amp;#39;.&amp;#39;, it is insufficient.&lt;/p&gt;
&lt;p&gt;### Risk Assessment
As easy_install and package_index are deprecated, the exploitation surface is reduced.
However, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.&lt;/p&gt;
&lt;p&gt;### Impact
An attacker would be allowed to write files to arbitrary locations on th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5rjg-fvgr-3xxf</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-47273 — setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-47273</link>
      <description>msrc_CVE-2025-47273</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-47273</guid>
    </item>
    <item>
      <title>OESA-2026-3376 — python-setuptools security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3376</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: python-setuptools&lt;/p&gt;
&lt;p&gt;Setuptools is a collection of enhancements to the Python distutils that allow you to more easily build and distribute Python packages, especially ones that have dependencies on other packages.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.(CVE-2025-47273)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: python-setuptools&lt;/p&gt;
&lt;p&gt;Setuptools is a collection of enhancements to the Python distutils that allow you to more easily build and distribute Python packages, especially ones that have dependencies on other packages.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.(CVE-2025-47273)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3376</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10539-1 — oci-cli-3.76.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10539-1</link>
      <description>&lt;p&gt;oci-cli-3.76.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;oci-cli-3.76.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10539-1</guid>
    </item>
    <item>
      <title>PYSEC-2025-49</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-49</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: setuptools&lt;/p&gt;
&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: setuptools&lt;/p&gt;
&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-49</guid>
    </item>
    <item>
      <title>RHSA-2025:10787 — Red Hat Security Advisory: Red Hat OpenShift Builds 1.4.1</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10787</link>
      <description>&lt;p&gt;setuptools: Path Traversal Vulnerability in setuptools PackageIndex&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;setuptools: Path Traversal Vulnerability in setuptools PackageIndex&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10787</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01693-1 — Security update for python36-setuptools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01693-1</link>
      <description>&lt;p&gt;Security update for python36-setuptools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python36-setuptools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01693-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-47273</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-47273</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:14.04:LTS: python-setuptools, Ubuntu:Pro:16.04:LTS: python-setuptools, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-setuptools, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:20.04:LTS: setuptools, Ubuntu:22.04:LTS: setuptools, Ubuntu:Pro:22.04:LTS: python-setuptools, Ubuntu:24.04:LTS: setuptools&lt;/p&gt;
&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:14.04:LTS: python-setuptools, Ubuntu:Pro:16.04:LTS: python-setuptools, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-setuptools, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:20.04:LTS: setuptools, Ubuntu:22.04:LTS: setuptools, Ubuntu:Pro:22.04:LTS: python-setuptools, Ubuntu:24.04:LTS: setuptools&lt;/p&gt;
&lt;p&gt;setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-47273</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1433 — Red Hat Enterprise Linux (python-setuptools): Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1433</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1433</guid>
    </item>
  </channel>
</rss>
