No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 01 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in pip, the package installer for Python. A remote attacker can exploit this vulnerability by tricking a victim into installing a malicious Python wheel. This wheel contains specially crafted entry-point names that use directory traversal or absolute paths. This allows pip to write generated script wrappers outside the intended installation directory, leading to arbitrary file overwrite. This can severely impact system integrity and availability, and in certain scenarios, may lead to arbitrary code execution. | pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. |
| Title | python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite | pip can extract console_scripts and gui_scripts outside installation directory |
| References |
| |
| Metrics |
cvssV4_0
|
Thu, 28 May 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pypa
Pypa pip |
|
| Vendors & Products |
Pypa
Pypa pip |
Thu, 28 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in pip, the package installer for Python. A remote attacker can exploit this vulnerability by tricking a victim into installing a malicious Python wheel. This wheel contains specially crafted entry-point names that use directory traversal or absolute paths. This allows pip to write generated script wrappers outside the intended installation directory, leading to arbitrary file overwrite. This can severely impact system integrity and availability, and in certain scenarios, may lead to arbitrary code execution. | |
| Title | python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2026-06-02T12:02:53.513Z
Reserved: 2026-05-14T20:21:04.562Z
Link: CVE-2026-8643
Updated: 2026-06-01T18:55:02.964Z
Status : Awaiting Analysis
Published: 2026-06-01T17:17:35.770
Modified: 2026-06-02T14:17:14.750
Link: CVE-2026-8643
OpenCVE Enrichment
Updated: 2026-06-01T18:45:34Z