Record summary

CVE-2026-8643 has a selected CVSS score of 4.1 (medium).

Description

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 1, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 100Source data: 100 of 171 entries available
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List24.0 to < 26.1.2affected

Exploit Intelligence

Browse Red Hat / Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9

Default status: affected

CVE ListVersion data not supplied

Migration Toolkit for Applications 8

Browse Red Hat / Migration Toolkit for Applications 8mta/mta-rhel9-operator

Default status: affected

CVE ListVersion data not supplied

Migration Toolkit for Virtualization

Browse Red Hat / Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel9-operator

Default status: affected

CVE ListVersion data not supplied

Migration Toolkit for Virtualization

Browse Red Hat / Migration Toolkit for Virtualizationmtv-candidate/mtv-rhel9-operator

Default status: affected

CVE ListVersion data not supplied

OpenShift Lightspeed

Browse Red Hat / OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9

Default status: unaffected

CVE ListVersion data not supplied

OpenShift Lightspeed

Browse Red Hat / OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9

Default status: unaffected

CVE ListVersion data not supplied

OpenShift Service Mesh 3

Browse Red Hat / OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9-operator

Default status: unaffected

CVE ListVersion data not supplied

Pen Drive Powered by Red Hat Lightspeed

Browse Red Hat / Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat AI Inference Server

Browse Red Hat / Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9

Default status: affected

CVE ListVersion data not supplied

References

Showing 12 of 42