CVE-2026-8643: Pypa Pip

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Affected products

  • Pypa Pip: before 26.1.2 (fixed in 26.1.2)

Published 2026-06-01. Last modified 2026-09-16.