What is CVE-2026-47764?
CVE-2026-47764 is a path traversal vulnerability found in the 'pdm' Python package manager. This flaw occurs in versions before 2.27.0 through the 'write_to_fs' function when handling symlink/hardlink support in the installer. Users are advised to upgrade pdm to version 2.27.0 or later to mitigate the issue.
Azərbaycanca: CVE-2026-47764, Python-un 'pdm' paket menecerində aşkar edilmiş path traversal zəifliyidir. Bu boşluq, 2.27.0 versiyasından əvvəlki pdm qurğularında 'write_to_fs' funksiyası vasitəsilə simvolik link (symlink) dəstəyi zamanı yaranır. İstifadəçilərə pdm-i ən azı 2.27.0 versiyasına yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What software is affected by CVE-2026-47764?
CVE-2026-47764 affects the 'pdm' Python package manager.
To which version should pdm be upgraded to mitigate CVE-2026-47764?
Users are advised to upgrade pdm to version 2.27.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.