Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-01708

Опубликовано: 31 янв. 2026
Источник: fstec
CVSS3: 3.5
CVSS2: 4
EPSS Низкий

Описание

Уязвимость функции commonprefix() модуля pip языка программирования Python связана с неверным ограничением имени пути к каталогу. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить доступ на добавление и изменение произвольных файлов

Вендор

ООО «Ред Софт»
Google Inc
Python Software Foundation

Наименование ПО

РЕД ОС
Android Studio
Python-pip

Версия ПО

8.0 (РЕД ОС)
2025.2.3.9 (Android Studio)
26.0 (Python-pip)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4)
Низкий уровень опасности (базовая оценка CVSS 3.1 составляет 3,5)
Низкий уровень опасности (оценка CVSS 4.0 составляет 2)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/pypa/pip/pull/13777
https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735
Для РЕД ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-1703

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 32%
0.0039
Низкий

3.5 Low

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 3.5
redos
4 месяца назад

Уязвимость python-pip

ubuntu
6 месяцев назад

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

CVSS3: 3.9
redhat
6 месяцев назад

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

nvd
6 месяцев назад

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

msrc
6 месяцев назад

Limited path traversal when installing wheel archives

EPSS

Процентиль: 32%
0.0039
Низкий

3.5 Low

CVSS3

4 Medium

CVSS2