MEDIUMVulnerability

CVE-2026-8643

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Properties

severity
MEDIUM
score
5.5
cve_id
CVE-2026-8643
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
published_at
2026-06-01T17:17:35.770
last_modified
2026-08-05T13:24:54.313

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-8643 — Ninja Signal Threat Intelligence | Ninja Signal