Pip console_scripts path flaw enables entry point out-of-dir
CVE-2026-8643 Published on June 1, 2026
pip can extract console_scripts and gui_scripts outside installation directory
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Vulnerability Analysis
CVE-2026-8643 can be exploited with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-8643 has been classified to as a Directory traversal vulnerability or weakness.
Products Associated with CVE-2026-8643
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-8643 are published in these products:
Affected Versions
Python Packaging Authority pip:- Version 24.0 and below 26.1.2 is affected.
- Version 0:4.6.30-2.el8ap and below * is unaffected.
- Version 0:4.6.30-2.el9ap and below * is unaffected.
- Version 0:4.7.14-3.el9ap and below * is unaffected.
- Version 0:25.2-3.el10_2.5 and below * is unaffected.
- Version 0:25.2-3.el9_8.5 and below * is unaffected.
- Version 1784049109 and below * is unaffected.
- Version 1782711769 and below * is unaffected.
- Version 1782713671 and below * is unaffected.
- Version 1782761510 and below * is unaffected.
- Version 1783969139 and below * is unaffected.
- Version 1785753810 and below * is unaffected.
- Version 1782763840 and below * is unaffected.
- Version 1786638573 and below * is unaffected.
- Version 26.1.1-3.1.hum1 and below * is unaffected.
- Version 26.1.2-1.hum1 and below * is unaffected.
- Version 1786481481 and below * is unaffected.
- Version 1783082430 and below * is unaffected.
- Version 1783024305 and below * is unaffected.
- Version 1783342900 and below * is unaffected.
- Version 1783998418 and below * is unaffected.
- Version 1783998418 and below * is unaffected.
- Version 1782475830 and below * is unaffected.
- Version 1782475830 and below * is unaffected.
- Version 1782929133 and below * is unaffected.
- Version 1782928984 and below * is unaffected.
- Version 1782968171 and below * is unaffected.
- Version 1782929069 and below * is unaffected.
- Version 1782928977 and below * is unaffected.
- Version 1782915416 and below * is unaffected.
- Version 1782915184 and below * is unaffected.
- Version 1782914833 and below * is unaffected.
- Version 1782914721 and below * is unaffected.
- Version 1782914751 and below * is unaffected.
- Version 1782914629 and below * is unaffected.
- Version 1782915056 and below * is unaffected.
- Version 1782916020 and below * is unaffected.
- Version 1782914960 and below * is unaffected.
- Version 1782914644 and below * is unaffected.
- Version 1782914706 and below * is unaffected.
- Version 1782915015 and below * is unaffected.
- Version 1782914779 and below * is unaffected.
- Version 1782914653 and below * is unaffected.
- Version 1783010225 and below * is unaffected.
- Version 1782887848 and below * is unaffected.
- Version 1782471555 and below * is unaffected.
- Version 1782471579 and below * is unaffected.
- Version 1783073038 and below * is unaffected.
- Version 1782991170 and below * is unaffected.
- Version 1782471656 and below * is unaffected.
- Version 1782471663 and below * is unaffected.
- Version 1783069204 and below * is unaffected.
- Version 1782991170 and below * is unaffected.
- Version 1782133213 and below * is unaffected.
- Version 1782726504 and below * is unaffected.
- Version 1782135464 and below * is unaffected.
- Version 1782136276 and below * is unaffected.
- Version 1782135346 and below * is unaffected.
- Version 1782132167 and below * is unaffected.
- Version 1782132207 and below * is unaffected.
- Version 1782132237 and below * is unaffected.
- Version 1782132240 and below * is unaffected.
- Version 1782132286 and below * is unaffected.
- Version 1782132236 and below * is unaffected.
- Version 1782132163 and below * is unaffected.
- Version 1782132297 and below * is unaffected.
- Version 1786612415 and below * is unaffected.
- Version 1786612637 and below * is unaffected.
- Version 1786635926 and below * is unaffected.
- Version 1787073866 and below * is unaffected.
- Version 1787073936 and below * is unaffected.
- Version 1787073873 and below * is unaffected.
- Version 1787073459 and below * is unaffected.
- Version 1787073611 and below * is unaffected.
- Version 1787073451 and below * is unaffected.
- Version 1787073451 and below * is unaffected.
- Version 1786613209 and below * is unaffected.
- Version 1787121387 and below * is unaffected.
- Version 1787074331 and below * is unaffected.
- Version 1787073913 and below * is unaffected.
- Version 1787074078 and below * is unaffected.
- Version 1787073929 and below * is unaffected.
- Version 1787073605 and below * is unaffected.
- Version 1787073546 and below * is unaffected.
- Version 1787073717 and below * is unaffected.
- Version 1787073713 and below * is unaffected.
- Version 1787073593 and below * is unaffected.
- Version 1782485441 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.