Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2863
  • PyPI/pdm
PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing 13 Jul
  • Fix available
  • Severity - 8.4 (High)
PYSEC-2026-2861
  • PyPI/pdm
PDM wheel installation leads to Path Traversal via overridden write_to_fs 13 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2862
  • PyPI/pdm
PDM: Project-Local State and Config Writes Follow Symlinks 13 Jul
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-1763
  • PyPI/pdm
PDM Trojan Lockfile 07 Jul
  • Fix available
  • Severity - 7.8 (High)
GHSA-qq6c-99pv-prvf
  • PyPI/pdm
PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing 11 Jun
  • Fix available
  • Severity - 8.4 (High)
GHSA-78v8-vpjp-cjqh
  • PyPI/pdm
PDM wheel installation leads to Path Traversal via overridden write_to_fs 10 Jun
  • Fix available
  • Severity - 7.1 (High)
GHSA-ghq2-5c67-fprm
  • PyPI/pdm
PDM: Project-Local State and Config Writes Follow Symlinks 10 Jun
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-j44v-mmf2-xvm9
  • PyPI/pdm
PDM Trojan Lockfile 20 Oct 2023
  • No fix available
  • Severity - 7.8 (High)