CVE-2026-47763: CWE-61: UNIX Symbolic Link (Symlink) Following in pdm-project pdm
CVE-2026-47763 is a medium severity vulnerability in the Python package manager pdm prior to version 2.27.0. It allows an attacker to exploit symbolic link (symlink) following when pdm writes project-local state or configuration files without symlink protection. This can lead to arbitrary file overwrite relative to the privileges of the user running pdm. The issue affects files such as pdm.toml, .pdm-python, and .python-version. The vulnerability has been fixed in pdm version 2.27.0.
AI Analysis
Technical Summary
The vulnerability arises because pdm versions before 2.27.0 write project-local configuration and state files without checking for symlinks, allowing an attacker who controls a malicious repository to place symlinks that pdm will follow and overwrite the symlink targets. Specifically, Config.__init__() resolves the pdm.toml path and _save_config() writes to the resolved target file. If pdm.toml is a symlink, pdm config -l updates the target file instead of refusing the write. Other project-local persistence files like .pdm-python and .python-version are similarly affected but without the TOML parsing constraint. This creates an arbitrary file clobber primitive with the privileges of the invoking user. The issue is tracked as CWE-61 (Improper Resolution of Symbolic Links) and has been fixed in version 2.27.0.
Potential Impact
An attacker who can supply a malicious repository with crafted symlinks can cause pdm to overwrite arbitrary files on the local filesystem with the privileges of the user running pdm. This can lead to local privilege escalation or corruption of important files. The vulnerability requires local access or the ability to influence the repository content used by pdm. The CVSS 4.0 score is 6.8 (medium severity), reflecting local attack vector, low attack complexity, no privileges required, but user interaction needed and high impact on integrity.
Mitigation Recommendations
Upgrade pdm to version 2.27.0 or later, where this symlink following issue has been fixed. Until then, avoid using pdm with untrusted repositories that could contain malicious symlinks. There is no official patch link provided, but the vendor has fixed the issue in version 2.27.0. Patch status is confirmed by the vendor advisory stating the fix is in 2.27.0.
CVE-2026-47763: CWE-61: UNIX Symbolic Link (Symlink) Following in pdm-project pdm
Description
CVE-2026-47763 is a medium severity vulnerability in the Python package manager pdm prior to version 2.27.0. It allows an attacker to exploit symbolic link (symlink) following when pdm writes project-local state or configuration files without symlink protection. This can lead to arbitrary file overwrite relative to the privileges of the user running pdm. The issue affects files such as pdm.toml, .pdm-python, and .python-version. The vulnerability has been fixed in pdm version 2.27.0.
CVSS v4.0
Score 6.8medium
Affected software
pdm-project
pdm
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because pdm versions before 2.27.0 write project-local configuration and state files without checking for symlinks, allowing an attacker who controls a malicious repository to place symlinks that pdm will follow and overwrite the symlink targets. Specifically, Config.__init__() resolves the pdm.toml path and _save_config() writes to the resolved target file. If pdm.toml is a symlink, pdm config -l updates the target file instead of refusing the write. Other project-local persistence files like .pdm-python and .python-version are similarly affected but without the TOML parsing constraint. This creates an arbitrary file clobber primitive with the privileges of the invoking user. The issue is tracked as CWE-61 (Improper Resolution of Symbolic Links) and has been fixed in version 2.27.0.
Potential Impact
An attacker who can supply a malicious repository with crafted symlinks can cause pdm to overwrite arbitrary files on the local filesystem with the privileges of the user running pdm. This can lead to local privilege escalation or corruption of important files. The vulnerability requires local access or the ability to influence the repository content used by pdm. The CVSS 4.0 score is 6.8 (medium severity), reflecting local attack vector, low attack complexity, no privileges required, but user interaction needed and high impact on integrity.
Mitigation Recommendations
Upgrade pdm to version 2.27.0 or later, where this symlink following issue has been fixed. Until then, avoid using pdm with untrusted repositories that could contain malicious symlinks. There is no official patch link provided, but the vendor has fixed the issue in version 2.27.0. Patch status is confirmed by the vendor advisory stating the fix is in 2.27.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T22:36:16.881Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a722802bf8831d53935aa23
Added to database: 08/04/2026, 17:57:22 UTC
Last enriched: 08/12/2026, 15:36:12 UTC
Last updated: 09/18/2026, 22:01:35 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.