Skip to content

uv is vulnerable to arbitrary file write through entry point names

Moderate severity GitHub Reviewed Published May 18, 2026 in astral-sh/uv

No open alerts for this advisory

Give feedback on Dependabot alerts