What is CVE-2026-13346?
This vulnerability in pip allows files to be installed to arbitrary locations on disk due to improper handling of doubly-encoded package URLs, specifically when installing wheels. It only succeeds when downloading from a malicious package index.
Azərbaycanca: pip-də aşkar edilmiş bu zəiflik, quraşdırma zamanı ikili kodlaşdırılmış URL-lərin düzgün idarə olunmaması səbəbindən faylların diskdə özbaşına yerlərə yazılmasına imkan verir. Bu, yalnız zərərli paket indeksindən quraşdırma edildikdə baş verir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Under what condition can CVE-2026-13346 be successfully exploited?
This vulnerability only succeeds when downloading from a malicious package index.
What is the consequence of improper handling of doubly-encoded URLs in CVE-2026-13346?
It allows files to be installed to arbitrary locations on disk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.