wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

Project Subscriptions

Vendors Products
Wheel Project Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8rrh-rw8j-w5fx Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack
Ubuntu USN Ubuntu USN USN-8221-1 wheel vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:10184 cve-icon
https://access.redhat.com/errata/RHSA-2026:13545 cve-icon
https://access.redhat.com/errata/RHSA-2026:14020 cve-icon
https://access.redhat.com/errata/RHSA-2026:1504 cve-icon
https://access.redhat.com/errata/RHSA-2026:17599 cve-icon
https://access.redhat.com/errata/RHSA-2026:1902 cve-icon
https://access.redhat.com/errata/RHSA-2026:1939 cve-icon
https://access.redhat.com/errata/RHSA-2026:1942 cve-icon
https://access.redhat.com/errata/RHSA-2026:19712 cve-icon
https://access.redhat.com/errata/RHSA-2026:20089 cve-icon
https://access.redhat.com/errata/RHSA-2026:2090 cve-icon
https://access.redhat.com/errata/RHSA-2026:2106 cve-icon
https://access.redhat.com/errata/RHSA-2026:2139 cve-icon
https://access.redhat.com/errata/RHSA-2026:2675 cve-icon
https://access.redhat.com/errata/RHSA-2026:2681 cve-icon
https://access.redhat.com/errata/RHSA-2026:2694 cve-icon
https://access.redhat.com/errata/RHSA-2026:2695 cve-icon
https://access.redhat.com/errata/RHSA-2026:2710 cve-icon
https://access.redhat.com/errata/RHSA-2026:2754 cve-icon
https://access.redhat.com/errata/RHSA-2026:2762 cve-icon
https://access.redhat.com/errata/RHSA-2026:2823 cve-icon
https://access.redhat.com/errata/RHSA-2026:2865 cve-icon
https://access.redhat.com/errata/RHSA-2026:2866 cve-icon
https://access.redhat.com/errata/RHSA-2026:2900 cve-icon
https://access.redhat.com/errata/RHSA-2026:2925 cve-icon
https://access.redhat.com/errata/RHSA-2026:3461 cve-icon
https://access.redhat.com/errata/RHSA-2026:3462 cve-icon
https://access.redhat.com/errata/RHSA-2026:3713 cve-icon
https://access.redhat.com/errata/RHSA-2026:3782 cve-icon
https://access.redhat.com/errata/RHSA-2026:3958 cve-icon
https://access.redhat.com/errata/RHSA-2026:3959 cve-icon
https://access.redhat.com/errata/RHSA-2026:3960 cve-icon
https://access.redhat.com/errata/RHSA-2026:4185 cve-icon
https://access.redhat.com/errata/RHSA-2026:4215 cve-icon
https://access.redhat.com/errata/RHSA-2026:4271 cve-icon
https://access.redhat.com/errata/RHSA-2026:4942 cve-icon
https://access.redhat.com/errata/RHSA-2026:5119 cve-icon
https://access.redhat.com/errata/RHSA-2026:6192 cve-icon
https://access.redhat.com/errata/RHSA-2026:6555 cve-icon
https://access.redhat.com/errata/RHSA-2026:6562 cve-icon
https://access.redhat.com/errata/RHSA-2026:6565 cve-icon
https://access.redhat.com/errata/RHSA-2026:7250 cve-icon
https://access.redhat.com/security/cve/CVE-2026-24049 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2431959 cve-icon
https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef cve-icon cve-icon cve-icon
https://github.com/pypa/wheel/releases/tag/0.46.2 cve-icon cve-icon cve-icon
https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-24049 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-24049 cve-icon
History

Wed, 18 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Wheel Project
Wheel Project wheel
CPEs cpe:2.3:a:wheel_project:wheel:*:*:*:*:*:python:*:*
Vendors & Products Wheel Project
Wheel Project wheel

Fri, 23 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.46.1 and below, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2. wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Pypa
Pypa wheel
Vendors & Products Pypa
Pypa wheel

Fri, 23 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 22 Jan 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 Jan 2026 04:30:00 +0000

Type Values Removed Values Added
Description wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.46.1 and below, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.
Title wheel Allows Arbitrary File Permission Modification via Path Traversal
Weaknesses CWE-22
CWE-732
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-12T12:04:37.362Z

Reserved: 2026-01-20T22:30:11.778Z

Link: CVE-2026-24049

cve-icon Vulnrichment

Updated: 2026-08-12T12:04:37.362Z

cve-icon NVD

Status : Modified

Published: 2026-01-22T05:16:23.157

Modified: 2026-08-12T12:17:55.967

Link: CVE-2026-24049

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-22T04:02:08Z

Links: CVE-2026-24049 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T04:00:08Z

Weaknesses