CVE 4.1 MEDIUM

pip can extract console_scripts and gui_scripts outside installation directory_CVE-2026-8643

4.1 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Description

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Basic Information

ID CVE-2026-8643
Source PSF
Published Jun 1, 2026 at 15:01
Modified Jun 1, 2026 at 15:07

Affected Product

Vendor Python Packaging Authority
Product pip
Affected Versions Python Packaging Authority pip 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.