Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8643

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

A flaw was found in pip, the package installer for Python. A remote attacker can exploit this vulnerability by tricking a victim into installing a malicious Python wheel. This wheel contains specially crafted entry-point names that use directory traversal or absolute paths. This allows pip to write generated script wrappers outside the intended installation directory, leading to arbitrary file overwrite. This can severely impact system integrity and availability, and in certain scenarios, may lead to arbitrary code execution.

Отчет

This Important flaw in pip's wheel installation process allows for arbitrary file overwrite due to path traversal. An attacker could exploit this by convincing a user to install a specially crafted malicious Python wheel. While file overwrites are limited to the installing user's permissions, using pip install with elevated privileges in Red Hat environments significantly increases the potential impact, potentially leading to system integrity compromise or arbitrary code execution.

Меры по смягчению последствий

To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using pip install with elevated privileges, such as sudo, when installing wheels. Additionally, administrators should inspect entry_points.txt within wheels for path separators or absolute paths before installation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Migration Toolkit for Applications 8mta/mta-rhel9-operatorAffected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel9-operatorAffected
Migration Toolkit for Virtualizationmtv-candidate/mtv-rhel9-operatorWill not fix
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9-operatorNot affected
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Affected
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Affected
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2460927python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite

EPSS

Процентиль: 24%
0.0032
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 5.5
nvd
около 2 месяцев назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

msrc
около 2 месяцев назад

pip can extract console_scripts and gui_scripts outside installation directory

CVSS3: 5.5
debian
около 2 месяцев назад

pip would treat console_scripts and gui_scripts as paths instead of fi ...

suse-cvrf
около 1 месяца назад

Security update for python-pip

EPSS

Процентиль: 24%
0.0032
Низкий

8 High

CVSS3