CVE-2026-8643: Pypa Pip
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Affected products
- Pypa Pip: before 26.1.2 (fixed in 26.1.2)
Published 2026-06-01. Last modified 2026-09-16.