CVE-2026-1703 — When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation dire — CVE Database · The Intelligence Room