Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-13327

22
FAUCET Score

CVE-2025-13327 describes a medium-severity flaw in the uv package manager, allowing arbitrary code execution through specially crafted ZIP archives during package resolution or installation. This vulnerability requires high privileges and user interaction, as an attacker must trick a user into installing a malicious package. There is currently no evidence of active exploitation, public exploit code, or significant community discussion beyond a single mention.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.9.6CPE matchmatch criteria
cpe:2.3:a:astral:uv:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

6.3MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.3
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 34th percentile among its peer group of 74 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

rustpatch availablevia ghsa
Product: uvFixed in: 0.9.6
redhatvendor investigatingvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis-preview/vllm-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-rocm-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-training-rocm64-torch28-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/model-opt-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-vllm-cpu-rhel9

Vendor Advisories (2)

rustGHSA-v653-r55g-hcmgmedium

uv has ZIP payload obfuscation through parsing differentials

Feb 27, 2026
redhatCVE-2025-13327Moderate

uv: uv: Specially crafted ZIP archives lead to arbitrary code execution due to parsing differentials

Oct 29, 2025

References

access.redhat.com / security/cve/CVE-2025-13327
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
github.com / astral-sh/uv
Product
github.com / astral-sh/uv/commit/da659fee4898a73dbc75070f3e82d49f745e4628
Patch
github.com / astral-sh/uv/security/advisories/GHSA-pqhf-p39g-3x64
Vendor Advisory