CVE-2026-8643

MEDIUM CVSS 4.0: 4.1 EPSS 0.47%
Updated Sep 16, 2026
Pypa
Parameter Value
CVSS 4.1 (MEDIUM)
Affected Versions before 26.1.2
Fixed In 26.1.2
Type CWE-22 (Path Traversal)
Vendor Pypa
Public PoC No

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Pypa Pip
cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*
— 26.1.2

References 42

https://github.com/pypa/pip/pull/14000
cna@python.org
https://mail.python.org/archives/list/security-announce@python.org/thread/YV63U…
cna@python.org
http://www.openwall.com/lists/oss-security/2026/06/01/5
af854a3a-2127-422b-91ae-364da2661108
https://access.redhat.com/errata/RHSA-2026:33313
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34374
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34456
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34739
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34740
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34741
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34748
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34749
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34750
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34752
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34756
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34758
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34760
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34765
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34772
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34773
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34774
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34775
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34776
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34777
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34778
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34780
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34891
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:36193
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:36315
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:37275
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:37283
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:42078
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:42079
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:42132
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:42144
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:42644
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/security/cve/CVE-2026-8643
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://bugzilla.redhat.com/show_bug.cgi?id=2460927
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:50479
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:54760
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:56347
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60520
0b0ca135-0b70-47e7-9f44-1890c2a1c46c