CVE-2026-8643

Published: May 28, 2026Last modified: June 3, 2026

Description

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpy3-pipFixed (22.3.1-r5)
25 LTSpy3-pipFixed (25.1.1-r2)
Streampy3-pipFixed (26.1.1-r1)
Hardened Containers23 LTSpy3-pipFixed (22.3.1-r5)
25 LTSpy3-pipFixed (25.1.1-r2)
Streampy3-pipFixed (26.1.1-r1)

References

ON THIS PAGE