StackRadar

CVE-2026-8643

High

Advisory

Published 1 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,275
of 17,790 indexed, latest versions
Container images
1,223
deployed by those charts
Fix available
1 of 2
affected packages

pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

Carried by container images the latest versions of 1,275 of 17,790 indexed charts deploy, on 1,223 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more26.1.21,217
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed139
OSV records
GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
Also known as
PYSEC-2026-196

Charts affected

1,275 by stars
ChartLatestAffected imagesRadar Score
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
pip@24.2
26.1.2
opea/embedding-tei:1.05c9639de61c1
pip@24.0
26.1.2
opea/llm-tgi:1.00c25aab3f106
pip@24.0
26.1.2
opea/reranking-tei:1.0e48613afb191
pip@24.2
26.1.2
opea/retriever-redis:1.0eb746b263705
pip@24.0
26.1.2

Open the chart page →

36,661
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
pip@24.2
26.1.2
opea/llm-tgi:1.00c25aab3f106
pip@24.0
26.1.2

Open the chart page →

26,489
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
pip@24.2
26.1.2
opea/llm-tgi:1.00c25aab3f106
pip@24.0
26.1.2

Open the chart page →

26,060
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
pip@24.2
26.1.2
opea/llm-docsum-tgi:1.002f9e8fa5d71
pip@24.0
26.1.2

Open the chart page →

26,535
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
pip@24.0
26.1.2

Open the chart page →

4,829
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
pip@24.2
26.1.2

Open the chart page →

4,865
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
pip@24.0
26.1.2

Open the chart page →

4,363
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
pip@24.2
26.1.2

Open the chart page →

4,629
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
pip@24.0
26.1.2

Open the chart page →

4,842
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
pip@24.2
26.1.2

Open the chart page →

8,877
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
pip@24.0
26.1.2

Open the chart page →

4,160
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
pip@24.2
26.1.2

Open the chart page →

4,994
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
pip@21.2.4
26.1.2

Open the chart page →

5,321
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
pip@22.0.4
26.1.2

Open the chart page →

4,662
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
pip@24.0
26.1.2

Open the chart page →

1,514
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
monitoringthl-chartsVerified publisher0.1.11 of 10See more

monitoring thl-charts 0.1.1

1 of the 10 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
pip@21.2.4
26.1.2

Open the chart page →

18,908
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
pip@20.2.2
26.1.2

Open the chart page →

4,434
todolist-charttodolist-chart0.1.72 of 10See more

todolist-chart todolist-chart 0.1.7

2 of the 10 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
pip@24.0
26.1.2
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

6,974
test0tohlejezkouska0.1.01 of 2See more

test0 tohlejezkouska 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
pip@22.0.4
26.1.2

Open the chart page →

3,308
netbirdtotmicro1.8.21 of 4See more

netbird totmicro 1.8.2

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
netbirdio/dashboard:v2.22.215a3aab9a345
pip@20.3.4
26.1.2

Open the chart page →

5,966
traefik-external-dns-controllertraefik-external-dns-operator2.2.01 of 1See more

traefik-external-dns-controller traefik-external-dns-operator 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
pip@24.0
26.1.2

Open the chart page →

1,462
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
pip@24.3.1
26.1.2

Open the chart page →

1,082
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
pip@22.3.1
26.1.2

Open the chart page →

3,164
orchestratremolo3.1.561 of 5See more

orchestra tremolo 3.1.56

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/tremolosecurity/python-slim-nonroot/python3:1.0.094f64e1f40cb
pip@23.1.2
26.1.2

Open the chart page →

2,863
tfy-grafanatruefoundryVerified publisher0.1.211 of 3See more

tfy-grafana truefoundry 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
pip@25.3
26.1.2

Open the chart page →

1,063
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
pip@25.3
26.1.2

Open the chart page →

4,529
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
pip@9.0.3
26.1.2

Open the chart page →

1,733
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pip@22.0.4
26.1.2

Open the chart page →

8,370
phonebook-chartusuladams2Verified publisher0.2.13 of 3See more

phonebook-chart usuladams2 0.2.1

3 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.1.2
paulkellerman/resultserver-app:1.0381eeccb0618
pip@22.3
26.1.2
paulkellerman/webserver-app:latest5a37b74f61b9
pip@22.3
26.1.2

Open the chart page →

3,176
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
pip@23.0.1
26.1.2

Open the chart page →

14,383
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pip@24.3.1
26.1.2

Open the chart page →

4,769
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
pip@24.0
26.1.2
vcnngr/telegram-rebot:latest30f1f05e57a6
pip@24.0
26.1.2

Open the chart page →

4,830
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.4
26.1.2
no fix listed

Open the chart page →

9,396
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed

Open the chart page →

4,360
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
bugsink/bugsink:2ecdd84587746
pip@25.0.1
26.1.2

Open the chart page →

4,097
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
pip@22.1.2
26.1.2

Open the chart page →

3,392
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pip@25.2
python-pip@24.0+dfsg-1ubuntu1.2
26.1.2
no fix listed

Open the chart page →

7,696
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
thecloudspark/app-vote:1.0c7da7417a86a
pip@21.1.1
26.1.2

Open the chart page →

3,030
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_vote:v13a856afb02a3
pip@22.0.4
26.1.2

Open the chart page →

8,287
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_vote:v13a856afb02a3
pip@22.0.4
26.1.2

Open the chart page →

8,287
waldur-site-agentwaldur-site-agentVerified publisher1.0.71 of 1See more

waldur-site-agent waldur-site-agent 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
pip@24.2
26.1.2

Open the chart page →

534
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
pip@25.1.1
python-pip@25.1.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

3,906
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
pip@26.0.1
26.1.2

Open the chart page →

629
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pip@23.3.2
26.1.2

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
pip@21.1.3
26.1.2

Open the chart page →

11,167
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pip@23.0.1
26.1.2

Open the chart page →

6,540

Container images carrying it

1,223 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
neilpeterson/aks-helloworld:v1fb47732ef36b
pip@9.0.1
26.1.2
1
neilpeterson/chart-tweet:latest64fd8dab075f
pip@9.0.1
26.1.2
1
neilpeterson/get-tweet:v28b645ac1a23e
pip@10.0.1
26.1.2
1
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
pip@9.0.1
26.1.2
1
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pip@9.0.1
26.1.2
1
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
pip@9.0.2
26.1.2
1
neilpeterson/osba-storage-demo:latest29d229ab446e
pip@9.0.1
26.1.2
1
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
pip@10.0.1
26.1.2
1
neilpeterson/process-tweet:latest39ce9f92e899
pip@10.0.1
26.1.2
1
netbirdio/dashboard:v2.22.215a3aab9a345
pip@20.3.4
26.1.2
1
netbirdio/dashboard:v2.90.101b59e1c905c9
pip@20.3.4
26.1.2
1
netbirdio/dashboard:v2.90.2332cc31f5f35
pip@20.3.4
26.1.2
1
netbirdio/dashboard:v2.13.188b5fb704a8c
pip@20.3.4
26.1.2
1
netboxcommunity/netbox:v3.2.83d652dca5351
pip@22.2.2
26.1.2
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pip@24.0
26.1.2
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pip@26.0.1
26.1.2
1
neuvector/manager:5.6.19e729010b7eb
pip@24.2
26.1.2
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
pip@20.2.3
26.1.2
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
pip@22.3.1
26.1.2
1
nlmacamp/check_mk:latest5dbb8589f824
pip@10.0.1
26.1.2
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
python-pip@25.1.1+dfsg-1
no fix listed
1
nyurik/alpine-python3-requests:lateste0553236e3eb
pip@21.1.3
26.1.2
1
octoprint/octoprint:1.4.0106c26efcd8a
pip@20.3.1
26.1.2
1
octoprint/octoprint:1.6.1ea3bffae2470
pip@21.1.2
26.1.2
1
odaniait/aws-kubectl:latest3fff8a8570ec
pip@20.0.2
26.1.2
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
pip@24.2
26.1.2
1
oled01/automx2:2025.1.105d3e398e675
pip@25.1.1
26.1.2
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
pip@9.0.1
python-pip@9.0.1-2.3~ubuntu1.18.04.1
26.1.2
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
pip@9.0.3
python-pip@8.1.1-2ubuntu0.4
26.1.2
no fix listed
1
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
pip@23.0.1
26.1.2
1
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
pip@23.0.1
26.1.2
1
omkara25/simple-microservice-app-user-service:v2d62cba548580
pip@23.0.1
26.1.2
1
onyxdotapp/onyx-backend:latest473fdffe4e67
pip@26.0.1
26.1.2
1
opea/asr:1.025dd26d9cd09
pip@24.0
26.1.2
1
opea/chatqna:1.038c51b791efa
pip@24.2
26.1.2
1
opea/codegen:1.058f91683892d
pip@24.2
26.1.2
1
opea/codetrans:1.0e2436483b73d
pip@24.2
26.1.2
1
opea/docsum:1.03eaa91849512
pip@24.2
26.1.2
1
opea/guardrails-tgi:1.0262c6048aab8
pip@24.2
26.1.2
1
opea/guardrails-tgi:latestf68bec6a1271
pip@24.3.1
26.1.2
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
pip@24.0
26.1.2
1
opea/speecht5:1.0249afad3d268
pip@24.2
26.1.2
1
opea/tts:1.0257ae94709e9
pip@24.0
26.1.2
1
opea/web-retriever-chroma:1.0fe08165d7770
pip@24.2
26.1.2
1
openbas/caldera-server:5.1.0a277796d9724
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pip@25.0.1
26.1.2
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
pip@25.2
26.1.2
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pip@25.2
26.1.2
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
pip@24.2
26.1.2
1
opencsghq/label-studio:v2.5.047e22aa71870
pip@25.1.1
26.1.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.