Code Execution Flaw in uv Product by Astral
CVE-2025-13327

6.3MEDIUM

Key Information:

Vendor

Astral-sh

Vendor
CVE Published:
27 February 2026

What is CVE-2025-13327?

A flaw exists in the uv product that can permit an adversary to execute unauthorized code during the package resolution or installation process. This vulnerability arises from the exploitation of parsing differentials within specially crafted ZIP archives. The issue necessitates user interaction to install the compromised package, raising the stakes for users during installation. It is crucial for administrators and users of the uv product to apply all relevant security measures and updates to mitigate potential risks associated with this flaw.

Affected Version(s)

uv 0 < 0.9.6

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.