Executive brief
uv is a fast Python package and project manager. A vulnerability in how it handles package uninstallation could allow a specially crafted, malicious package to delete arbitrary files on a user's system. To be affected, a user must manually install and then uninstall a malformed package, which could lead to the loss of important system or personal files.
Technical details
A path traversal vulnerability exists in uv versions 0.11.5 and earlier due to insufficient validation of RECORD entries in Python wheels. The RECORD file, which lists files to be removed during uninstallation, can contain relative paths (e.g., using '../') that point outside the intended installation directory. While uv does not use these paths for file creation, it honors them during the uninstallation process. An attacker can exploit this by distributing a malformed wheel that, when uninstalled by a user, triggers the deletion of arbitrary files the user has permissions to modify. Exploitation requires the attacker to guess the directory depth of the installation prefix. The issue is fixed in version 0.11.6 by validating and stripping invalid RECORD entries.
Affected products
- Astral uv <= 0.11.5
Timeline
- 2026-04-09: disclosed
- 2026-04-10: advisory
- 2026-04-10: patched: Fixed in version 0.11.6