MEDIUMCVSS 5.5Vulnerability

CVE-2026-8643

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Properties

severity
MEDIUM
cvss_severity
MEDIUM
cvss_score
5.5
epss_score
0.00466
retrieved_at
2026-09-25T15:12:24+00:00
last_source
FIRST EPSS
score
5.5
cve_id
CVE-2026-8643
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
signal_observed_at
2026-09-11T17:54:52+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
published_at
2026-06-01T17:17:35.770
last_modified
2026-09-16T13:18:08.000
epss_percentile
0.37683

Related Entities (4)

ENRICHED_BY (1)

→[Source]FIRST EPSS

HAS_WEAKNESS (1)

→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

→[Source]NVD

AFFECTS_PRODUCT (1)

→[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-8643 (CVSS 5.5) — Ninja Signal Threat Intelligence | Ninja Signal