Skip to content

Python setuptools needs to be updated to 78.1.1 or later to address CVE-2025-47273 #22165

@aaronmaxlevy

Description

@aaronmaxlevy

CVE-2025-47273 is a high severity vulnerability in setuptools involving path traversal leading to arbitrary file writing.

Currently, protobuf is pinned to setuptools version 70.3.0 which is vulnerable. setuptools should be updated to 78.1.1 or later in order to address this.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions