Skip to main content

Vendor/product archive

pypa / pip CVEs

Beta · best-effort

9 CVEs tagged to pypa / pip0 Critical, 2 High, 5 Medium, 2 Low, 0 Unrated.

CVE-2026-8643

Published Jun 1, 2026

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points…

CVSS 4.1 · Medium
evidence mentions
39
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2023-5752

Published Oct 25, 2023

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20225

Published May 8, 2020

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a pri…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8991

Published Nov 24, 2014

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1888

Published Aug 17, 2013

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1629

Published Aug 6, 2013

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to exec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1