---
title: 'Topic: pip'
canonical_url: https://portal.chinng-lab-srv.dev/topics/pip.md
content_kind: topic
updated_at: '2026-07-14T06:44:25Z'
---

# Topic: pip

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/pip.md
- Last updated: 2026-07-14T06:44:25Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=pip
- MCP: portal_search(q="pip")

## Related categories

- security/library

## Related entities

- MLB Pipeline
- Artist from Mali
- HashMark
- Papa Fries 6 Cheese Fondue
- PyTerrier retrieval pipelines
- XPath Agent
- Tariq Shaheen
- Search Console
- scripts/upload_portal_items.py
- HashTag
- Structure and Interpretation of Computer Programs Course

## Latest articles

- [CVE-2026-6357: pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere](https://portal.chinng-lab-srv.dev/security/library/security-20260714-36ddaf.md): pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
- [CVE-2026-3219: pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files](https://portal.chinng-lab-srv.dev/security/library/security-20260714-2b057f.md): pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
- [CVE-2026-1703: pip Path Traversal vulnerability](https://portal.chinng-lab-srv.dev/security/library/security-20260711-23efcc.md): pip Path Traversal vulnerability
- [CVE-2025-8869: pip's fallback tar extraction doesn't check symbolic links point to extraction directory](https://portal.chinng-lab-srv.dev/security/library/security-20260711-0a6e6e.md): pip's fallback tar extraction doesn't check symbolic links point to extraction directory
- [CVE-2026-8643: pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory](https://portal.chinng-lab-srv.dev/security/library/security-20260711-dccc73.md): pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
- [CVE-2026-8643 — pip](https://portal.chinng-lab-srv.dev/security/library/security-20260711-4047e8.md): pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed out…
- [CVE-2026-6357: pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere](https://portal.chinng-lab-srv.dev/security/library/security-20260711-1aac96.md): pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
- [CVE-2026-3219: pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files](https://portal.chinng-lab-srv.dev/security/library/security-20260711-a0d84f.md): pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
- [CVE-2026-1703: pip Path Traversal vulnerability](https://portal.chinng-lab-srv.dev/security/library/security-20260711-23941b.md): pip Path Traversal vulnerability
- [CVE-2025-8869: pip's fallback tar extraction doesn't check symbolic links point to extraction directory](https://portal.chinng-lab-srv.dev/security/library/security-20260711-41c2a0.md): pip's fallback tar extraction doesn't check symbolic links point to extraction directory
