Feed/CVE-2026-8643
CVE-2026-8643MEDIUMCVSS 5.5

CVE-2026-8643

Published Jun 1, 2026·Updated Aug 19, 2026

NVD Description

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Affected Packages (1)

pipPYPI
Fixed in 26.1.2

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free