Uncontrolled Search Path Element Affecting python/cpython package, versions [,3.15.0b3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-PYTHONCPYTHON-17845237
  • published6 Jul 2026
  • disclosed16 Jun 2026
  • creditUnknown

Introduced: 16 Jun 2026

CVE-2026-12003  (opens in a new tab)
CWE-427  (opens in a new tab)

How to fix?

Upgrade python/cpython to version 3.15.0b3 or higher.

Overview

Affected versions of this package are vulnerable to Uncontrolled Search Path Element via the VPATH process used during build and installation on Windows platforms. An attacker can gain elevated privileges by creating a malicious Modules/setup.local file and an alternative Lib directory outside the intended installation directory, which may be discovered and loaded by the interpreter if directory permissions allow such manipulation. This is only exploitable if the installation uses the legacy EXE installer for all users and the directory two levels above the Python installation directory is writable by low-privilege users.

Workaround

This vulnerability can be mitigated by migrating to the new Python install manager for per-user installations or by preemptively creating and restricting access to the Modules directory.

CVSS Base Scores

version 4.0
version 3.1