CVE-2026-24049: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-24049 is a path traversal and incorrect permission assignment vulnerability in the Python wheel command-line tool (pypa/wheel) that allows an attacker to modify file permissions on arbitrary system files outside the intended extraction directory. It affects wheel versions 0.40.0 through 0.46.1, as well as downstream consumers such as setuptools (which vendors wheel). The vulnerability was disclosed on January 22, 2026, and fixed in version 0.46.2. CVSS v3.1 scores range from 5.5 (Medium, per NVD/NIST) to 7.1 (High, per GitHub CNA), reflecting differing assessments of availability impact (GitHub Advisory, wheel Release 0.46.2).

Technical details

The root cause lies in the wheel.cli.unpack.unpack function (CWE-22, CWE-732): after extracting each archive entry via wf.extract(zinfo, destination) — which safely sanitizes the output path — the code then applies chmod using the unsanitized zinfo.filename from the archive header rather than the actual extracted path returned by wf.extract(). This means a crafted wheel containing a path traversal entry such as ../../etc/passwd will cause chmod to target the real system file at that path, even though the file extraction itself was safe. The attack requires local access and user interaction (a victim must run wheel unpack on the malicious file), but requires no privileges. The fix (commit 7a7d2de) changes the chmod call to use the sanitized path returned by wf.extract() (GitHub Advisory, Fix Commit).

Impact

Successful exploitation allows an unprivileged attacker to set arbitrary Unix permissions (e.g., 0o777) on critical system files such as /etc/passwd, SSH authorized keys, or executable scripts, making them world-writable. This can enable privilege escalation — for example, by making a root-owned script writable and then injecting malicious code — or facilitate arbitrary code execution. Confidentiality is not directly impacted, but integrity of critical system resources is severely compromised, and depending on which files are targeted, availability may also be affected (GitHub Advisory).

Exploitability

A public proof-of-concept (PoC) exploit script (gen_poc.py / exploit.py) is included in the GitHub Security Advisory and demonstrates confirmed exploitation against both wheel and setuptools._vendor.wheel. An additional PoC tool (wheelaudit) is available on GitHub at https://github.com/kriskimmerle/wheelaudit. As of the time of disclosure, there is no evidence of in-the-wild exploitation. The EPSS score is approximately 0.023% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Craft a malicious wheel file: Use a script (as demonstrated in the public PoC) to create a ZIP-based .whl file containing a ZipInfo entry with a path traversal filename (e.g., ../../etc/passwd or ../../home/user/.ssh/authorized_keys) and external_attr set to (0o100000 | 0o777) << 16 to encode world-writable permissions.
  2. Authenticate the malicious entry: Include the traversal path in the wheel's RECORD file with a valid SHA-256 hash of the payload content, so the wheel library's integrity check passes.
  3. Deliver the wheel to the victim: Social-engineer or otherwise cause a user with access to sensitive files to run wheel unpack evil-1.0-py3-none-any.whl (or trigger it via a build pipeline that calls setuptools._vendor.wheel.cli.unpack.unpack).
  4. Trigger the vulnerable chmod: When unpack() iterates over the archive's file list, it calls wf.extract(zinfo, destination) (which safely redirects the traversal), but then calls destination.joinpath(zinfo.filename).chmod(permissions) using the unsanitized zinfo.filename, resolving to the real target file outside the destination.
  5. Achieve privilege escalation or code execution: With the target file now world-writable (e.g., a root-owned script or /etc/passwd), the attacker can modify its contents to inject commands, add a new root user, or otherwise escalate privileges (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected permission changes (e.g., mode 0777) on critical files such as /etc/passwd, /etc/shadow, ~/.ssh/authorized_keys, or system scripts; files outside a wheel unpack destination directory with recently modified mtime or ctime on permission metadata.
  • Process: Execution of wheel unpack or Python processes invoking setuptools._vendor.wheel.cli.unpack.unpack against untrusted or externally sourced .whl files; unexpected chmod system calls on files outside the intended extraction directory (detectable via auditd or strace).
  • Logs: auditd records showing chmod/fchmod syscalls on sensitive paths (e.g., /etc/passwd) initiated by a Python process; shell history or CI/CD logs showing wheel unpack invocations on unfamiliar wheel files.
  • Network: Download of .whl files from untrusted or unexpected sources (e.g., non-PyPI URLs) immediately prior to an unpack operation.

Mitigation and workarounds

Upgrade the wheel package to version 0.46.2 or later, which fixes the vulnerability by using the sanitized path returned by wf.extract() for the chmod operation (wheel Release 0.46.2, Fix Commit). Organizations using setuptools should also update it, as it vendors the vulnerable wheel code. As an interim workaround, avoid running wheel unpack on wheel files from untrusted or unverified sources. IBM, Oracle, Red Hat, SUSE, Splunk, and other downstream vendors have issued their own advisories and patches for affected products (IBM Netezza Advisory, Oracle April 2026 Bulletin, Splunk Advisory).

Community reactions

The vulnerability was reported by researcher kilkat, remediated by agronholm (wheel maintainer), and reviewed by henryiii, as credited in the GitHub Security Advisory. Red Hat assigned the CVE a Moderate severity rating and issued multiple errata (RHSA-2026:1504, RHSA-2026:1902, RHSA-2026:1939, and others) for affected RHEL and related products. IBM published advisories for numerous affected products including API Connect, Netezza Appliance, Cloud Pak for Business Automation, and watsonx Orchestrate. The vulnerability received coverage on Linux security news aggregators and German-language security blogs (pro-linux.de), and was noted on Bluesky and Mastodon by CVE tracking accounts (GitHub Advisory, Red Hat CVE).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

wheel

Fixed

sid

wheel: 0.46.3-1

Fixed

trixie

wheel

Affected

Ubuntu

Fixed

bionic (esm-apps)

wheel

Not Affected

devel

wheel

Not Affected

focal (esm-apps)

wheel

Not Affected

jammy

wheel

Not Affected

jammy (esm-apps)

wheel

Not Affected

noble

wheel

Affected

noble (esm-apps)

wheel: 0.42.0-2ubuntu0.1~esm1

Fixed

resolute

wheel

Not Affected

RHEL / CentOS

Fixed

OpenShift

el9:openshift4/ose-ansible-rhel9-operator-0:v4.16.0

Fixed

RHEL 8

:appstream:python3.12-wheel-0:0.41.2-4.el8_10.src

Fixed

RHEL 9

:appstream:python3.12-wheel-0:0.41.2-3.el9_4.1.src

Fixed

RHEL 10

python-wheel-1:0.41.2-5.el10_0.1.src

Fixed

Alpine

Fixed

edge

py3-wheel: 0.46.3-r0

Fixed

v3.22

py3-wheel: 0.46.3-r0

Fixed

v3.23

py3-wheel: 0.46.3-r0

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management