SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-8643

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

MEDIUM 4.1EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS 4.0
4.1 MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
pypa/pip
Source
cna@python.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.