Skip to main content
HIGH

CVE-2025-47273

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

CVSS v3

8.8

HIGH

EPSS Score

1.5 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

Technical details

Published
2025-05-17
Last Modified
2025-06-12

Frequently asked questions

What is CVE-2025-47273?

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

Is CVE-2025-47273 actively exploited?

A proof-of-concept exploit exists for CVE-2025-47273, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2025-47273?

CVE-2025-47273 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2025-47273 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key