PT-2026-45480 · Pypi+2 · Pip+2

·

CVE-2026-8643

·

Published

2026-05-28

·

Updated

2026-07-21

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pip (affected versions not specified)
Description pip fails to sanitize the resolved absolute path to the installation directory when treating console scripts and gui scripts as paths rather than file names. This allows entry points to be installed outside the intended installation directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36193
ALSA-2026:36315
BDU:2026-10841
CLEANSTART-2026-KY55512
CLEANSTART-2026-NR60332
CLEANSTART-2026-SA70432
CLEANSTART-2026-UC45646
CLEANSTART-2026-YC81398
CVE-2026-8643
ECHO-E120-768D-97D2
GHSA-WF93-45JW-7689
OESA-2026-2544
OESA-2026-2629
OESA-2026-2630
OESA-2026-2631
OPENSUSE-SU-2026:10940-1
OPENSUSE-SU-2026:20993-1
PYSEC-2026-196
RHSA-2026:34891
RHSA-2026:36193
RHSA-2026:36315
RHSA-2026:42078
RHSA-2026:42079
SUSE-SU-2026:22300-1
SUSE-SU-2026:2634-1

Affected Products

Red Os
Rocky Linux
Pip