Vulnerability in wheel Command Line Tool Allows File Permission Modifications
CVE-2026-24049
What is CVE-2026-24049?
The wheel command line tool, used for handling Python wheel files, contains a vulnerability that permits unauthorized modification of file permissions during the extraction process. The issue arises from the implementation of the unpack function, which in versions 0.46.1 and below, inadequately verifies file permissions. Attackers can exploit this by crafting malicious wheel files that manipulate permissions of critical system files, such as /etc/passwd and SSH keys, enabling privilege escalation or arbitrary code execution. This vulnerability has been addressed in version 0.46.2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wheel >= 0.40.0, < 0.46.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
