Package impact

python PyPI / magic-wormhole

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-42448 low 3.5 3.5 1d ago Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed python
CVE-2026-32116 unknown 3mo ago Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite python