https://seclists.org/oss-sec/2026/q2/766: [oss-security][CVE-2026-8643] pip can extract console_scripts and gui_scripts outside installation dictory
Published Jun 1, 2026
·Updated
Affected Software
1 affected component
pypi/pip<26.1.2
Frequently Asked Questions
1
What is the severity of CVE-2026-8643?
CVE-2026-8643 has been classified with a high severity due to its potential for exposing sensitive data.
2
How do I fix CVE-2026-8643?
To fix CVE-2026-8643, update pip to version 26.1.2 or later.
3
What versions are affected by CVE-2026-8643?
CVE-2026-8643 affects all pip versions prior to 26.1.2.
4
What kind of impact does CVE-2026-8643 have?
CVE-2026-8643 allows extraction of console_scripts and gui_scripts outside the intended installation directory, potentially leading to data compromise.
5
Is there a workaround for CVE-2026-8643?
There is no official workaround for CVE-2026-8643; the recommended action is to upgrade pip.