CVE-2025-13327
This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an…
Does this matter?
Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an attacker-controlled package.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.15% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1286
- Affected
- astral/uv
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2025-13327Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2407263Issue Tracking
- https://github.com/astral-sh/uvProduct
- https://github.com/astral-sh/uv/commit/da659fee4898a73dbc75070f3e82d49f745e4628Patch
- https://github.com/astral-sh/uv/security/advisories/GHSA-pqhf-p39g-3x64Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.