pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
References
Configurations
History
10 Jul 2026, 12:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Jul 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 Jul 2026, 12:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
03 Jul 2026, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Jul 2026, 12:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jun 2026, 03:21
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Jun 2026, 16:52
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Pypa
Pypa pip |
|
| CPE | cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:* | |
| References | () https://github.com/pypa/pip/pull/14000 - Issue Tracking, Patch | |
| References | () https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/ - Mailing List, Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/06/01/5 - Mailing List, Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
02 Jun 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-22 |
01 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-01 17:17
Updated : 2026-07-16 12:18
NVD link : CVE-2026-8643
Mitre link : CVE-2026-8643
CVE.ORG link : CVE-2026-8643
JSON object : View
Products Affected
pypa
- pip
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
