PatchSiren cyber security CVE debrief
CVE-2026-47763 pdm-project CVE debrief
PatchSiren debrief for CVE-2026-47763: PDM project-local file clobber via symlink attack. The vulnerability in PDM versions prior to 2.27.0 allows for arbitrary file clobbering via symlinks, posing a risk to PDM users and maintainers. This issue is resolved in version 2.27.0. Users should assess exposure and apply the fix to prevent potential symlink attacks. The CVE record and NVD entry provide details on the vulnerability, which is categorized as a medium priority issue. PDM users and maintainers should review project-local PDM configurations and state files for potential symlink attacks and monitor PDM operations for suspicious activity.
- Vendor
- pdm-project
- Product
- pdm
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-04
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-04
- Advisory updated
- 2026-09-08
Who should care
PDM users and maintainers should assess exposure and apply the fix to prevent potential symlink attacks. The vulnerability poses a risk to PDM users and maintainers, and they should review project-local PDM configurations and state files for potential symlink attacks and monitor PDM operations for suspicious activity. The issue is categorized as a medium priority issue, and PDM users and maintainers should verify PDM versions in use and check if they are 2
Why it matters
CVE-2026-47763 allows for arbitrary file clobbering via symlinks in PDM versions prior to 2.27.0, posing a risk to PDM users and maintainers. The issue is resolved in version 2.27.0.
- Potential for data loss or corruption due to arbitrary file clobbering
- Risk of privilege escalation via symlink attacks
- Need for verification of PDM version and configuration
- Potential for security bypass via project-local file manipulation
Technical summary
PDM versions prior to 2.27.0 write project-local state or configuration files without symlink protection, allowing for arbitrary file clobbering via symlinks. This issue is resolved in version 2.27.0. The vulnerability has a CVSS score of 6.8 and is classified as a medium severity issue. PDM users and maintainers should assess exposure and apply the fix to prevent potential symlink attacks. The issue allows for potential data loss or corruption due to arbitrary file clobbering, risk of privilege escalation via symlink attacks, and need for verification of PDM version and configuration.
Defensive priority
Medium priority for PDM users and maintainers
Recommended defensive actions
- Assess exposure by checking PDM versions in use and verifying if they are prior to 2.27.0
- Apply the fix by updating PDM to version 2.27.0 or later
- Review project-local PDM configurations and state files for potential symlink attacks
- Monitor PDM operations for suspicious activity
- Verify PDM configurations and state files for potential symlink attacks
- Perform a thorough review of PDM operations and configurations to ensure the fix has been applied correctly
- Track exceptions and retest remediated assets to ensure the vulnerability has been fully mitigated
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in PDM versions prior to 2.27.0, which allows for arbitrary file clobbering via symlinks. The issue is resolved in version 2.27.0. PDM users and maintainers should verify PDM versions in use and check if they are prior to 2.27.0. The vulnerability has a CVSS score of 6.8 and is classified as a medium severity issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47763 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47763
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47763 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47763
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/pdm-project/pdm/releases/tag/2.27.0
-
Source reference
Unverified legacy reference
URL: https://github.com/pdm-project/pdm/security/advisories/GHSA-ghq2-5c67-fprm
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.