CVE-2026-8643

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*

History

04 Jun 2026, 16:52

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*
References () https://github.com/pypa/pip/pull/14000 - () https://github.com/pypa/pip/pull/14000 - Issue Tracking, Patch
References () https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/ - () https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/ - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/06/01/5 - () http://www.openwall.com/lists/oss-security/2026/06/01/5 - Mailing List, Third Party Advisory
First Time Pypa
Pypa pip

02 Jun 2026, 14:17

Type Values Removed Values Added
CWE CWE-22

01 Jun 2026, 21:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/06/01/5 -

01 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 17:17

Updated : 2026-06-04 16:52


NVD link : CVE-2026-8643

Mitre link : CVE-2026-8643

CVE.ORG link : CVE-2026-8643


JSON object : View

Products Affected

pypa

  • pip
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')