CVE-2026-8643

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

  • Published Jun 1, 2026
  • CVSS 4.1 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2026-8643 at the National Vulnerability Database