CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.
References
Link Resource
https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef Patch
https://github.com/pypa/wheel/releases/tag/0.46.2 Product Release Notes
https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx Exploit Mitigation Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:10184
https://access.redhat.com/errata/RHSA-2026:13545
https://access.redhat.com/errata/RHSA-2026:14020
https://access.redhat.com/errata/RHSA-2026:1504
https://access.redhat.com/errata/RHSA-2026:17599
https://access.redhat.com/errata/RHSA-2026:1902
https://access.redhat.com/errata/RHSA-2026:1939
https://access.redhat.com/errata/RHSA-2026:1942
https://access.redhat.com/errata/RHSA-2026:19712
https://access.redhat.com/errata/RHSA-2026:20089
https://access.redhat.com/errata/RHSA-2026:2090
https://access.redhat.com/errata/RHSA-2026:2106
https://access.redhat.com/errata/RHSA-2026:2139
https://access.redhat.com/errata/RHSA-2026:2675
https://access.redhat.com/errata/RHSA-2026:2681
https://access.redhat.com/errata/RHSA-2026:2694
https://access.redhat.com/errata/RHSA-2026:2695
https://access.redhat.com/errata/RHSA-2026:2710
https://access.redhat.com/errata/RHSA-2026:2754
https://access.redhat.com/errata/RHSA-2026:2762
https://access.redhat.com/errata/RHSA-2026:2823
https://access.redhat.com/errata/RHSA-2026:2865
https://access.redhat.com/errata/RHSA-2026:2866
https://access.redhat.com/errata/RHSA-2026:2900
https://access.redhat.com/errata/RHSA-2026:2925
https://access.redhat.com/errata/RHSA-2026:3461
https://access.redhat.com/errata/RHSA-2026:3462
https://access.redhat.com/errata/RHSA-2026:3713
https://access.redhat.com/errata/RHSA-2026:3782
https://access.redhat.com/errata/RHSA-2026:3958
https://access.redhat.com/errata/RHSA-2026:3959
https://access.redhat.com/errata/RHSA-2026:3960
https://access.redhat.com/errata/RHSA-2026:4185
https://access.redhat.com/errata/RHSA-2026:4215
https://access.redhat.com/errata/RHSA-2026:4271
https://access.redhat.com/errata/RHSA-2026:4942
https://access.redhat.com/errata/RHSA-2026:5119
https://access.redhat.com/errata/RHSA-2026:6192
https://access.redhat.com/errata/RHSA-2026:6555
https://access.redhat.com/errata/RHSA-2026:6562
https://access.redhat.com/errata/RHSA-2026:6565
https://access.redhat.com/errata/RHSA-2026:7250
https://access.redhat.com/security/cve/CVE-2026-24049
https://bugzilla.redhat.com/show_bug.cgi?id=2431959
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json
Configurations

Configuration 1 (hide)

cpe:2.3:a:wheel_project:wheel:*:*:*:*:*:python:*:*

History

30 Jun 2026, 03:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:10184 -
  • () https://access.redhat.com/errata/RHSA-2026:13545 -
  • () https://access.redhat.com/errata/RHSA-2026:14020 -
  • () https://access.redhat.com/errata/RHSA-2026:1504 -
  • () https://access.redhat.com/errata/RHSA-2026:17599 -
  • () https://access.redhat.com/errata/RHSA-2026:1902 -
  • () https://access.redhat.com/errata/RHSA-2026:1939 -
  • () https://access.redhat.com/errata/RHSA-2026:1942 -
  • () https://access.redhat.com/errata/RHSA-2026:19712 -
  • () https://access.redhat.com/errata/RHSA-2026:20089 -
  • () https://access.redhat.com/errata/RHSA-2026:2090 -
  • () https://access.redhat.com/errata/RHSA-2026:2106 -
  • () https://access.redhat.com/errata/RHSA-2026:2139 -
  • () https://access.redhat.com/errata/RHSA-2026:2675 -
  • () https://access.redhat.com/errata/RHSA-2026:2681 -
  • () https://access.redhat.com/errata/RHSA-2026:2694 -
  • () https://access.redhat.com/errata/RHSA-2026:2695 -
  • () https://access.redhat.com/errata/RHSA-2026:2710 -
  • () https://access.redhat.com/errata/RHSA-2026:2754 -
  • () https://access.redhat.com/errata/RHSA-2026:2762 -
  • () https://access.redhat.com/errata/RHSA-2026:2823 -
  • () https://access.redhat.com/errata/RHSA-2026:2865 -
  • () https://access.redhat.com/errata/RHSA-2026:2866 -
  • () https://access.redhat.com/errata/RHSA-2026:2900 -
  • () https://access.redhat.com/errata/RHSA-2026:2925 -
  • () https://access.redhat.com/errata/RHSA-2026:3461 -
  • () https://access.redhat.com/errata/RHSA-2026:3462 -
  • () https://access.redhat.com/errata/RHSA-2026:3713 -
  • () https://access.redhat.com/errata/RHSA-2026:3782 -
  • () https://access.redhat.com/errata/RHSA-2026:3958 -
  • () https://access.redhat.com/errata/RHSA-2026:3959 -
  • () https://access.redhat.com/errata/RHSA-2026:3960 -
  • () https://access.redhat.com/errata/RHSA-2026:4185 -
  • () https://access.redhat.com/errata/RHSA-2026:4215 -
  • () https://access.redhat.com/errata/RHSA-2026:4271 -
  • () https://access.redhat.com/errata/RHSA-2026:4942 -
  • () https://access.redhat.com/errata/RHSA-2026:5119 -
  • () https://access.redhat.com/errata/RHSA-2026:6192 -
  • () https://access.redhat.com/errata/RHSA-2026:6555 -
  • () https://access.redhat.com/errata/RHSA-2026:6562 -
  • () https://access.redhat.com/errata/RHSA-2026:6565 -
  • () https://access.redhat.com/errata/RHSA-2026:7250 -
  • () https://access.redhat.com/security/cve/CVE-2026-24049 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2431959 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json -

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) wheel es una herramienta de línea de comandos para manipular archivos wheel de Python, según se define en PEP 427. En las versiones 0.40.0 a 0.46.1, la función unpack es vulnerable a la modificación de permisos de archivos debido a un manejo incorrecto de los permisos de archivos después de la extracción. La lógica confía ciegamente en el nombre de archivo del encabezado del archivo comprimido para la operación chmod, a pesar de que el propio proceso de extracción podría haber saneado la ruta. Los atacantes pueden crear un archivo wheel malicioso que, al ser descomprimido, cambia los permisos de archivos críticos del sistema (por ejemplo, /etc /passwd, claves SSH, archivos de configuración), permitiendo la escalada de privilegios o la ejecución de código arbitrario al modificar scripts ahora escribibles. Este problema ha sido solucionado en la versión 0.46.2.

18 Feb 2026, 14:56

Type Values Removed Values Added
CPE cpe:2.3:a:wheel_project:wheel:*:*:*:*:*:python:*:*
References () https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef - () https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef - Patch
References () https://github.com/pypa/wheel/releases/tag/0.46.2 - () https://github.com/pypa/wheel/releases/tag/0.46.2 - Product, Release Notes
References () https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx - () https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx - Exploit, Mitigation, Vendor Advisory
First Time Wheel Project
Wheel Project wheel

23 Jan 2026, 18:16

Type Values Removed Values Added
Summary (en) wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.46.1 and below, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2. (en) wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

22 Jan 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-22 05:16

Updated : 2026-07-21 12:17


NVD link : CVE-2026-24049

Mitre link : CVE-2026-24049

CVE.ORG link : CVE-2026-24049


JSON object : View

Products Affected

wheel_project

  • wheel
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-732

Incorrect Permission Assignment for Critical Resource