← back
CVE-2026-8643mediumCWE-22

pip can extract console_scripts and gui_scripts outside installation directory

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.1epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N