CVE-2026-8643
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
8.0
HIGH
CVSS 3.1
EPSS 0.32%
Description
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
How to fix CVE-2026-8643
To remediate CVE-2026-8643, upgrade the affected package to a fixed version below.
- —upgrade to 26.1.2 or later
- —upgrade to 26.1.2 or later
Is CVE-2026-8643 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 26.1.2
- from 0, < 26.1.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH8.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |