Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wheelaudit — Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD tampering, command shadowing, secrets, zip bombs. Zero deps. | Kitploit
Tools/GitHubGitHub/kriskimmerle/wheelaudit
Static AnalysisVulnerability AnalysisCode AnalysisConfiguration AuditingMalware AnalysisDevSecOpsSecret DetectionSupply Chain Security
GitHubkriskimmerle/wheelaudit

wheelaudit

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD tampering, command shadowing, secrets, zip bombs. Zero deps.

3337 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

wheelaudit

Python Wheel File Security Scanner — scan .whl files for security issues before installation.

Motivated by recent CVEs in Python wheel handling:

  • CVE-2026-24049: Path traversal in wheel unpack allows permission manipulation of system files
  • CVE-2026-1703: Path traversal when pip installs wheel archives
  • Google GHSA-w97x-xxj5-gpjx: Zip parser differential vulnerability in Python wheels

Zero dependencies. Single file. Python 3.9+.

Why?

pip-audit checks if your packages have known CVEs. wheelaudit checks if a wheel file itself is structurally malicious — path traversal, tampered RECORD hashes, embedded secrets, command shadowing, zip bombs, and more. It's the difference between "is this package known-bad?" and "does this package look bad?"

Run it before pip install. Run it in CI. Run it on downloaded wheels you don't trust.

Installation

# Just copy the file
curl -O https://raw.githubusercontent.com/kriskimmerle/wheelaudit/main/wheelaudit.py
chmod +x wheelaudit.py

# Or clone the repo
git clone https://github.com/kriskimmerle/wheelaudit.git
cd wheelaudit

Usage

# Scan a wheel file
python3 wheelaudit.py package-1.0.0-py3-none-any.whl

# Scan multiple wheels
python3 wheelaudit.py *.whl

# Scan a directory of wheels
python3 wheelaudit.py ./wheels/

# CI mode: exit 1 if score below threshold
python3 wheelaudit.py package.whl --check --min-score 80

# JSON output for tooling integration
python3 wheelaudit.py package.whl --json

# Verbose mode with details
python3 wheelaudit.py package.whl -v

# Filter by severity
python3 wheelaudit.py package.whl --severity high

# Ignore specific rules
python3 wheelaudit.py package.whl --ignore WH11

# Read from stdin
cat package.whl | python3 wheelaudit.py --stdin

Rules

RuleSeverityDescription
WH01CRITICALPath traversal in filenames (../, absolute paths, null bytes)
WH02CRITICAL-HIGHRECORD file integrity (missing, tampered hashes, unlisted files)
WH03HIGH-LOWSuspicious file types (executables, pickle, archives, hidden files)
WH04CRITICALEntry point command shadowing (pip, python, sudo, etc.)
WH05CRITICALEmbedded secrets (API keys, tokens, private keys)
WH06CRITICAL-LOWFile permission issues (SUID/SGID, world-writable, executable data)
WH07HIGH-MEDIUMMetadata consistency (missing METADATA/WHEEL, structural issues)
WH08HIGHZip bomb detection (extreme compression ratios, oversized archives)
WH09HIGH-MEDIUMPEP 427 compliance (filename format, name/version mismatch)
WH10CRITICALNamespace collision (stdlib module shadowing)
WH11HIGH-MEDIUMMalicious code patterns (eval, exec, os.system, credential access)
WH12MEDIUM-LOWData file issues (scripts in .data/, oversized files)
WH13HIGHCRC32 manipulation (CVE-2025-1889 bypass pattern)
WH14HIGHExtension mismatch (ELF/PE binary disguised as .py/.txt)
WH15HIGH-MEDIUMSymlinks and duplicate filenames

15 rules, 5 severity levels

CRITICAL (20 points): Path traversal, SUID bits, embedded secrets, command shadowing, stdlib shadowing, RECORD hash tampering

HIGH (12 points): Missing RECORD, suspicious executables, zip bombs, CRC manipulation, extension mismatch, symlinks, credential harvesting patterns

MEDIUM (6 points): Backslash paths, missing metadata, PEP 427 issues, subprocess/network patterns

LOW (2 points): Hidden files, executable data files, large files

INFO (0 points): Legitimate native extensions, environment variable access

Example Output

Clean wheel (requests 2.32.5)

============================================================
requests 2.32.5 — B (88/100)
============================================================

  [HIGH]
    WH11 Suspicious pattern: __import__() — dynamic import (requests/packages.py)

  Summary: 1 high

Malicious wheel

============================================================
evil-pip 99.0.0 — F (0/100)
============================================================

  [CRITICAL]
    WH01 Path traversal in wheel archive (../../../etc/crontab)
    WH04 Entry point shadows system command: 'pip'
    WH04 Entry point shadows system command: 'python'
    WH05 Embedded secret: GitHub Personal Access Token (pip/__init__.py)

  [HIGH]
    WH02 File not listed in RECORD (../../../etc/crontab)
    WH03 Suspicious file type: .exe (pip/payload.exe)
    WH11 Suspicious pattern: os.system() — shell command execution
    WH11 Suspicious pattern: eval() call — dynamic code execution
    WH11 Suspicious pattern: SSH directory reference

  Summary: 4 critical, 5 high, 2 medium, 2 low

JSON Output

{
  "version": "0.1.0",
  "results": [
    {
      "path": "package-1.0.0-py3-none-any.whl",
      "score": 88,
      "grade": "B",
      "metadata": {
        "name": "package",
        "version": "1.0.0",
        "file_count": 15,
        "total_uncompressed_bytes": 45000
      },
      "findings": [
        {
          "rule": "WH11",
          "severity": "high",
          "message": "Suspicious pattern: __import__() — dynamic import",
          "file": "package/compat.py"
        }
      ],
      "summary": {
        "high": 1
      }
    }
  ]
}

CI Integration

GitHub Actions

- name: Audit wheel
  run: |
    python3 wheelaudit.py dist/*.whl --check --min-score 80

Pre-install gate

pip download some-package --no-deps -d /tmp/wheels
python3 wheelaudit.py /tmp/wheels/*.whl --check
pip install /tmp/wheels/*.whl

How It Works

wheelaudit treats every .whl file as an untrusted zip archive. It:

  1. Parses zip metadata without extracting (safe inspection)
  2. Checks archive structure for path traversal, symlinks, duplicates
  3. Verifies RECORD integrity — hashes and file lists
  4. Inspects file types — executables, binaries, hidden files
  5. Scans text content — secrets, malicious code patterns
  6. Validates PEP 427 compliance — filename, metadata, structure
  7. Detects known attack patterns — CVE-2026-24049, CRC manipulation, parser differentials

No files are extracted to disk. All analysis happens in memory.

Comparison

Featurewheelauditpip-auditsafetyGuardDog
Zero deps✅❌❌❌
Scans wheel contents✅❌❌✅
Path traversal detection✅❌❌❌
RECORD integrity✅❌❌❌
CVE database❌✅✅❌
Offline operation✅❌❌❌
Python 3.9+✅✅✅✅

wheelaudit complements pip-audit/safety — they check known vulnerabilities, wheelaudit checks the wheel itself.

License

MIT

Download Tool