PYSEC-2026-196

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pip/PYSEC-2026-196.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2026-196
Aliases
Published
2026-06-01T17:17:35Z
Modified
2026-07-13T16:51:12Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

References

Affected packages

PyPI / pip

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.1.2

Affected versions

0.*
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.*
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
6.*
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.*
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.*
9.0.0
9.0.1
9.0.2
9.0.3
10.*
10.0.0b1
10.0.0b2
10.0.0
10.0.1
18.*
18.0
18.1
19.*
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.*
20.0
20.0.1
20.0.2
20.1b1
20.1
20.1.1
20.2b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.3b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
21.*
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.*
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1b1
22.1
22.1.1
22.1.2
22.2
22.2.1
22.2.2
22.3
22.3.1
23.*
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.*
24.0
24.1b1
24.1b2
24.1
24.1.1
24.1.2
24.2
24.3
24.3.1
25.*
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.*
26.0
26.0.1
26.1
26.1.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/pip/PYSEC-2026-196.yaml"