What is CVE-2026-47781?
CVE-2026-47781 is a critical vulnerability in PDM package manager. In versions up to 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing arbitrary Python code execution from untrusted repositories. Users must update to the latest version immediately.
Azərbaycanca: CVE-2026-47781 PDM paket menecerində aşkarlanan kritik boşluqdur. 2.26.9 və əvvəlki versiyalarda, PDM işə salınarkən etibarsız repozitoriyalardan gələn `.pdm-plugins` qovluğundakı zərərli faylları avtomatik yükləyir və bu, uzaqdan kod icrasına səbəb ola bilər. İstifadəçilər dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which package manager is affected by CVE-2026-47781?
This vulnerability affects the PDM package manager.
How to protect against the CVE-2026-47781 vulnerability?
Users must update to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.