© 2025-2026 PySpect
First version without a known vulnerability: 0.11.15
uv is vulnerable to arbitrary file write through entry point names
Fixed in: 0.11.15
uv vulnerable to arbitrary file deletion through RECORD entries
Fixed in: 0.11.6
uv allows ZIP payload obfuscation through parsing differentials
Fixed in: 0.9.6
uv has differential in tar extraction with PAX headers
Fixed in: 0.9.5
uv allows ZIP payload obfuscation through parsing differentials
Fixed in: 0.8.6