Path Traversal Vulnerability in Setuptools Affects Python Package Management
CVE-2025-47273

7.7HIGH

Key Information:

Vendor

Pypa

Vendor
CVE Published:
17 May 2025

What is CVE-2025-47273?

A path traversal flaw in setuptools prior to version 78.1.1 allows attackers to write files to arbitrary locations on the filesystem by exploiting the vulnerabilities in the PackageIndex component. This issue could lead to significant security risks, including the potential for remote code execution, depending on how the affected package is implemented in the environment. Users are advised to update to version 78.1.1 or newer to mitigate this risk.

Affected Version(s)

setuptools < 78.1.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47273 : Path Traversal Vulnerability in Setuptools Affects Python Package Management