Logo
vulnerabilityCVE-2026-8643
Name
CVE-2026-8643
Source
NVD ( link)Debian ( link)
Description
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python-pip
Exploitable

Vulnerability Ratings#


4.1
CVSSv4
5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
26.1
Exploitable
openwrt
master
26.1.2-r1
Not Affected
openwrt
openwrt-25.12
23.3.1-r2
Exploitable