buildroot ▾
›
2025.02.x ▾
›
component
›
python-pip
Component Overview
Vulnerability Overview
Name
python-pip
Version
25.2
Type
library
Description
-
Licenses
MIT
PURL
pkg:pypi/pip@25.2
CPE
cpe:2.3:a:pypa:pip:25.2:-:*:*:*:*:*:*
Other Versions
#
Project
Branch
Version
buildroot
master
26.1
Vulnerabilities
#
Name
Analysis
Description
CVE-2026-8643
Exploitable
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.