Skip to content

CVE-2026-8643 (Medium) detected in pip-26.1.1-py3-none-any.whl #108

@mend-for-github-com

Description

@mend-for-github-com

CVE-2026-8643 - Medium Severity Vulnerability

Vulnerable Library - pip-26.1.1-py3-none-any.whl

The PyPA recommended tool for installing Python packages.

Library home page: https://files.pythonhosted.org/packages/3a/eb/fea4d1d51c49832120f7f285d07306db3960f423a2612c6057caf3e8196f/pip-26.1.1-py3-none-any.whl

Path to dependency file: /tmp/ws-scm/spotfire-python

Path to vulnerable library: /tmp/ws-ua_20260506063530_RVRPSW/python_WSYGMI/20260506063531/pip-26.1.1-py3-none-any.whl

Dependency Hierarchy:

  • pip-26.1.1-py3-none-any.whl (Vulnerable Library)

Found in base branch: main

Vulnerability Details

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Publish Date: 2026-06-01

URL: CVE-2026-8643

CVSS 4 Score Details (4.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: N/A
    • Scope: N/A
  • Impact Metrics:
    • Confidentiality Impact: N/A
    • Integrity Impact: N/A
    • Availability Impact: N/A

For more information on CVSS4 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-01

Fix Resolution: 26.1.2


  • Check this box to open an automated fix PR

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions