Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-8643

Опубликовано: 01 июн. 2026
Источник: debian

Описание

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-pipfixed26.1.2+dfsg-1package
python-pipno-dsatrixiepackage
python-pipno-dsabookwormpackage
python-pippostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2460927

  • Fixed by: https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb

  • Improvement to original fix: https://github.com/pypa/pip/pull/14001

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 8
redhat
4 месяца назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 5.5
nvd
4 месяца назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

msrc
3 месяца назад

pip can extract console_scripts and gui_scripts outside installation directory

suse-cvrf
3 месяца назад

Security update for python-pip