Zurück zur CVE-Übersicht
CVE-2026-8643
MEDIUM(5.5)CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Risk Signal Score14/100 — NIEDRIG
- CVSS 5.5 — Mittel
EPSS-Score
0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
5.5
Technische Schwere
Beschreibung
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Referenzen
- https://github.com/pypa/pip/pull/14000
- https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UE...
- http://www.openwall.com/lists/oss-security/2026/06/01/5
- https://access.redhat.com/errata/RHSA-2026:33313
- https://access.redhat.com/errata/RHSA-2026:34374
- https://access.redhat.com/errata/RHSA-2026:34456
- https://access.redhat.com/errata/RHSA-2026:34739
- https://access.redhat.com/errata/RHSA-2026:34740
- https://access.redhat.com/errata/RHSA-2026:34741
- https://access.redhat.com/errata/RHSA-2026:34748