Directory Traversal Affecting dask-kubernetes package, versions <2025.7.0-r8


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.28% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-WOLFILATEST-DASKKUBERNETES-15381363
  • published4 Mar 2026
  • disclosed22 Jan 2026

Introduced: 22 Jan 2026

CVE-2026-24049  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

Upgrade Wolfi dask-kubernetes to version 2025.7.0-r8 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream dask-kubernetes package and not the dask-kubernetes package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

CVSS Base Scores

version 3.1