CVE-2026-8643

unknown
Published 2026-06-01 · Modified 2026-06-01
CVSS v3
CVSS v4 NEW
4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
VIR risk

Description

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-8643 NameCVE-2026-8643 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus python-pip (PTS)bullseye20.3.4-4+deb11u1vulnerable bullseye…

CVE-2026-8643

NameCVE-2026-8643
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-pip (PTS)bullseye20.3.4-4+deb11u1vulnerable
bullseye (security)20.3.4-4+deb11u2vulnerable
bookworm23.0.1+dfsg-1vulnerable
trixie25.1.1+dfsg-1vulnerable
forky26.0.1+dfsg-1vulnerable
sid26.1.1+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-pipsource(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2460927

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://bugzilla.redhat.com/show_bug.cgi?id=2460927

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected
suse slesaffected

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.