云虫漏洞库

CVE-2026-8643 - pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. - 漏洞详情

漏洞编号:CVE-2026-8643

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-8643

CNNVD 编号:-

厂商/产品:pypa / pip

影响范围:cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*

CWE:CWE-22

发布/更新时间:2026-06-01 / 2026-08-28

漏洞描述

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

相关链接

相关漏洞

« 返回首页