Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-8643

Опубликовано: 01 июн. 2026
Источник: debian
EPSS Низкий

Описание

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-pipfixed26.1.2+dfsg-1package
python-pipno-dsatrixiepackage
python-pipno-dsabookwormpackage
python-pippostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2460927

  • Fixed by: https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb

  • Improvement to original fix: https://github.com/pypa/pip/pull/14001

EPSS

Процентиль: 24%
0.0032
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 8
redhat
2 месяца назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 5.5
nvd
около 2 месяцев назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

msrc
около 2 месяцев назад

pip can extract console_scripts and gui_scripts outside installation directory

suse-cvrf
около 1 месяца назад

Security update for python-pip

EPSS

Процентиль: 24%
0.0032
Низкий