---
schema_version: '1.0'
id: security-20260711-dccc73
url: https://osv.dev/vulnerability/GHSA-wf93-45jw-7689
url_hash: dccc73164085984af46538ee754001843ad34d356177379ca5549bd9b9357bc9
canonical_url: https://osv.dev/vulnerability/GHSA-wf93-45jw-7689
source: osv:ghsa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-8643
- GHSA-wf93-45jw-7689
- severity:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- pip
- PyPI
lang: en
published_at: '2026-06-01T18:31:53Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-11T06:39:54Z'
status: published
content_hash: b4bef386b039d2d9a055387610504a91a40c7a8f46f2fc0dc80acc7947c3adcf
license_note: full
summary: 'pip: Path traversal in console_scripts/gui_scripts entry point names allows
  installing scripts outside of target directory'
summary_source: rss
summary_en: 'pip: Path traversal in console_scripts/gui_scripts entry point names
  allows installing scripts outside of target directory'
entities:
- name: PyTerrier retrieval pipelines
  type: data
- name: XPath Agent
  type: artifact
- name: Search Console
  type: artifact
- name: scripts/upload_portal_items.py
  type: artifact
key_facts: []
related: []
related_auto:
- name: QueryExplorer
  type: system
  weight: 1.0
- name: Agent Openclaw
  type: person
  weight: 1.0
- name: Google
  type: organization
  weight: 1.0
- name: agent_n8n_1_bot
  type: organization
  weight: 1.0
- name: googlesearchconsole
  type: artifact
  weight: 1.0
title: 'CVE-2026-8643: pip: Path traversal in console_scripts/gui_scripts entry point
  names allows installing scripts outside of target directory'
---

# CVE-2026-8643: pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

## TL;DR
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

## Key Points
- cve / CVE-2026-8643 / GHSA-wf93-45jw-7689 / severity:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H / pip / PyPI

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
**Advisory:** GHSA-wf93-45jw-7689 (CVE-2026-8643)

**Affected (your watchlist):**
- `PyPI:pip` 24.0 → fixed in 26.1.2 [docker/docker-portal+docker/local+docker/mac]
- `PyPI:pip` 25.0.1 → fixed in 26.1.2 [docker/docker-graphrag+docker/docker-llmwiki+docker/docker-portal+docker/docker-strands+docker/local+docker/mac]
- `PyPI:pip` 25.1.1 → fixed in 26.1.2 [docker/docker-mcp]
- `PyPI:pip` 26.0.1 → fixed in 26.1.2 [docker/docker-llmwiki]

**Details:**
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

**References:**
- https://nvd.nist.gov/vuln/detail/CVE-2026-8643
- https://github.com/pypa/pip/pull/14000
- https://access.redhat.com/errata/RHSA-2026:33313
- https://access.redhat.com/errata/RHSA-2026:34776
- https://access.redhat.com/errata/RHSA-2026:34777
- https://access.redhat.com/errata/RHSA-2026:34778
- https://access.redhat.com/errata/RHSA-2026:34780
- https://access.redhat.com/errata/RHSA-2026:34891
- https://access.redhat.com/errata/RHSA-2026:36193
- https://access.redhat.com/errata/RHSA-2026:36315

_Data: OSV.dev (upstream: ghsa) — https://osv.dev/vulnerability/GHSA-wf93-45jw-7689_

## Source
元記事: [CVE-2026-8643: pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory](https://osv.dev/vulnerability/GHSA-wf93-45jw-7689) — published 2026-06-01T18:31:53Z
