setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.
History

Thu, 12 Jun 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
Python
Python setuptools
CPEs cpe:2.3:a:python:setuptools:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux
Python
Python setuptools
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 28 May 2025 15:30:00 +0000

Type Values Removed Values Added
References

Wed, 21 May 2025 03:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

threat_severity

Moderate


Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 17 May 2025 16:00:00 +0000

Type Values Removed Values Added
Description setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.
Title setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-17T15:46:11.399Z

Updated: 2025-05-28T15:03:15.516Z

Reserved: 2025-05-05T16:53:10.372Z

Link: CVE-2025-47273

cve-icon Vulnrichment

Updated: 2025-05-28T15:03:15.516Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-17T16:15:19.110

Modified: 2025-06-12T16:29:01.660

Link: CVE-2025-47273

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-17T15:46:11Z

Links: CVE-2025-47273 - Bugzilla