---
schema_version: '1.0'
id: security-20260711-4047e8
url: https://osv.dev/vulnerability/PYSEC-2026-196
url_hash: 4047e8bd03912d3eeb43414f81941ea3faf0b38f27de12027afbfe5987f53f6d
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-196
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-8643
- PYSEC-2026-196
- severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- pip
- PyPI
lang: en
published_at: '2026-06-01T17:17:35Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-14T06:42:55Z'
status: published
content_hash: 07987b42985836290f33866afe34d492129fb83a184d866a5d076e13b4e9b61f
license_note: full
summary: pip would treat console_scripts and gui_scripts as paths instead of file
  names without sanitizing the resolved absolute path to the installation directory,
  leading to entry points being installed outside the installation directory.
summary_source: rss
summary_en: pip would treat console_scripts and gui_scripts as paths instead of file
  names without sanitizing the resolved absolute path to the installation directory,
  leading to entry points being installed outside the installation directory.
entities:
- name: MLB Pipeline
  type: organization
related_auto: []
title: CVE-2026-8643 — pip
---

# CVE-2026-8643 — pip

## TL;DR
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

## Key Points
- cve / CVE-2026-8643 / PYSEC-2026-196 / severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N / pip / PyPI

## Details
**Severity:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
**Advisory:** PYSEC-2026-196 (CVE-2026-8643)

**Affected (your watchlist):**
- `PyPI:pip` 24.0 → fixed in 26.1.2 [docker/docker-portal+docker/local+docker/mac]
- `PyPI:pip` 25.0.1 → fixed in 26.1.2 [docker/docker-graphrag+docker/docker-llmwiki+docker/docker-portal+docker/docker-strands+docker/local+docker/mac]
- `PyPI:pip` 25.1.1 → fixed in 26.1.2 [docker/docker-mcp]
- `PyPI:pip` 26.0.1 → fixed in 26.1.2 [docker/docker-llmwiki]

**Details:**
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

**References:**
- http://www.openwall.com/lists/oss-security/2026/06/01/5
- https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/
- https://github.com/pypa/pip/pull/14000
- https://github.com/advisories/GHSA-wf93-45jw-7689

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-196_

## Source
元記事: [CVE-2026-8643 — pip](https://osv.dev/vulnerability/PYSEC-2026-196) — published 2026-06-01T17:17:35Z
