Skip to content

CVE-2026-8643 on CTRL-OS 26.05

Aliases: CVE-2026-8643

Packages: python3Packages.pip

Status: Plausible

Advisory Information

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Updates

2026-07-16 23:37 CEST

Metadata changes:

  • Status for package python3Packages.pip: “Plausible

2026-06-03 17:07 CEST

Metadata changes:

  • Status for package python3Packages.pip: “New