CVE-2023-5752

MEDIUM

pip < 23.3 - Command Injection via Mercurial VCS URL Configuration

Title source: llm
STIX 2.1

Description

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.

Scores

CVSS v3 5.5
EPSS 0.0048
EPSS Percentile 37.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (2)
pypa/pip < 23.3
pypi/pip 0 - 23.3PyPI
Published Oct 25, 2023
Tracked Since Feb 18, 2026