CVE-2026-8643

unknown
Published 2026-06-01 Β· Modified 2026-06-02
CVSS v3
β€”
CVSS v4 NEW
4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
VIR risk
β€”

Description

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2026-8643 NameCVE-2026-8643 Descriptionpip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub…

CVE-2026-8643

NameCVE-2026-8643
Descriptionpip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1138220

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-pip (PTS)bullseye20.3.4-4+deb11u1vulnerable
bullseye (security)20.3.4-4+deb11u2vulnerable
bookworm23.0.1+dfsg-1vulnerable
trixie25.1.1+dfsg-1vulnerable
forky26.1.1+dfsg-1vulnerable
sid26.1.2+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-pipsource(unstable)26.1.2+dfsg-11138220

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2460927
Fixed by: https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb
Improvement to original fix: https://github.com/pypa/pip/pull/14001

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://bugzilla.redhat.com/show_bug.cgi?id=2460927Fixed by: https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfbImprovement to original fix: https://github.com/pypa/pip/pull/14001

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected β€”
sid Fixed 26.1.2+dfsg-1
forky Affected β€”
bullseye Affected β€”
bookworm Affected β€”

References

CWEs

CWE-22

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.