ZeroHour

CVE-2025-13327

CVSS 3.1
6.3 medium
EPSS
<1%p5
Published
()
Modified
Description

A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an attacker-controlled package.

Vendors
astral
Products
uv
Weakness
CWE-1286
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.