PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47763 pdm-project CVE debrief

PatchSiren debrief for CVE-2026-47763: PDM project-local file clobber via symlink attack. The vulnerability in PDM versions prior to 2.27.0 allows for arbitrary file clobbering via symlinks, posing a risk to PDM users and maintainers. This issue is resolved in version 2.27.0. Users should assess exposure and apply the fix to prevent potential symlink attacks. The CVE record and NVD entry provide details on the vulnerability, which is categorized as a medium priority issue. PDM users and maintainers should review project-local PDM configurations and state files for potential symlink attacks and monitor PDM operations for suspicious activity.

Vendor
pdm-project
Product
pdm
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-04
Original CVE updated
2026-09-08
Advisory published
2026-08-04
Advisory updated
2026-09-08

Who should care

PDM users and maintainers should assess exposure and apply the fix to prevent potential symlink attacks. The vulnerability poses a risk to PDM users and maintainers, and they should review project-local PDM configurations and state files for potential symlink attacks and monitor PDM operations for suspicious activity. The issue is categorized as a medium priority issue, and PDM users and maintainers should verify PDM versions in use and check if they are 2

Why it matters

CVE-2026-47763 allows for arbitrary file clobbering via symlinks in PDM versions prior to 2.27.0, posing a risk to PDM users and maintainers. The issue is resolved in version 2.27.0.

  • Potential for data loss or corruption due to arbitrary file clobbering
  • Risk of privilege escalation via symlink attacks
  • Need for verification of PDM version and configuration
  • Potential for security bypass via project-local file manipulation

Technical summary

PDM versions prior to 2.27.0 write project-local state or configuration files without symlink protection, allowing for arbitrary file clobbering via symlinks. This issue is resolved in version 2.27.0. The vulnerability has a CVSS score of 6.8 and is classified as a medium severity issue. PDM users and maintainers should assess exposure and apply the fix to prevent potential symlink attacks. The issue allows for potential data loss or corruption due to arbitrary file clobbering, risk of privilege escalation via symlink attacks, and need for verification of PDM version and configuration.

Defensive priority

Medium priority for PDM users and maintainers

Recommended defensive actions

  • Assess exposure by checking PDM versions in use and verifying if they are prior to 2.27.0
  • Apply the fix by updating PDM to version 2.27.0 or later
  • Review project-local PDM configurations and state files for potential symlink attacks
  • Monitor PDM operations for suspicious activity
  • Verify PDM configurations and state files for potential symlink attacks
  • Perform a thorough review of PDM operations and configurations to ensure the fix has been applied correctly
  • Track exceptions and retest remediated assets to ensure the vulnerability has been fully mitigated

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in PDM versions prior to 2.27.0, which allows for arbitrary file clobbering via symlinks. The issue is resolved in version 2.27.0. PDM users and maintainers should verify PDM versions in use and check if they are prior to 2.27.0. The vulnerability has a CVSS score of 6.8 and is classified as a medium severity issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47763 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47763

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47763 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47763

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.