Weakness
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Affected products
- pypa pip
References
- https://github.com/pypa/pip/pull/14000
- https://mail.python.org/archives/list/[email protected]/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/
- http://www.openwall.com/lists/oss-security/2026/06/01/5
- https://access.redhat.com/errata/RHSA-2026:33313
- https://access.redhat.com/errata/RHSA-2026:34374
- https://access.redhat.com/errata/RHSA-2026:34456
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.