CVE-2026-8643
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.32%
- Published
- 2026-06-01
- Last modified
- 2026-09-16
Affected products
- Python Packaging Authority pip
- Python Packaging Authority pip