There is a  MEDIUM severity vulnerability affecting pip.

pip would incorrectly handle doubly-encoded package URLs from indexes
allowing for files to be installed to arbitrary locations on disk even when
installing wheels.

This vulnerability requires downloading or installing a package from a
malicious package index to succeed, malicious packages alone are not able
to exploit this vulnerability. Note that this vulnerability only materially
impacts users running `pip download` with the `--only-binary` option as
installing source distributions from an untrusted index is already an
unsafe operation that executes code during install time.

Please see the linked CVE ID for the latest information on affected
versions:

* https://www.cve.org/CVERecord?id=CVE-2026-13346
* https://github.com/pypa/pip/pull/14110
_______________________________________________
Security-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/security-announce.python.org
Member address: [email protected]

Reply via email to