CVE-2026-8643
HighAdvisory
Published 1 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.0
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,282
- of 17,790 indexed, latest versions
- Container images
- 1,231
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Carried by container images the latest versions of 1,282 of 17,790 indexed charts deploy, on 1,231 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pippypi | 1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more | 26.1.2 | 1,224 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 more | no fix listed | 141 |
- OSV records
- GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
- Also known as
- PYSEC-2026-196
Charts affected
1,282 by stars
Container images carrying it
1,231 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| nathanielvarona/ | b746a34e5597 | pip | 26.1.2 | 1 |
| ncsa/ | 0b738bbc8d70 | pip | 26.1.2 | 1 |
| neilpeterson/ | fb47732ef36b | pip | 26.1.2 | 1 |
| neilpeterson/ | 64fd8dab075f | pip | 26.1.2 | 1 |
| neilpeterson/ | 8b645ac1a23e | pip | 26.1.2 | 1 |
| neilpeterson/ | 6527b05d5d03 | pip | 26.1.2 | 1 |
| neilpeterson/ | f4940e84ed05 | pip | 26.1.2 | 1 |
| neilpeterson/ | 5859d68a6c9f | pip | 26.1.2 | 1 |
| neilpeterson/ | 29d229ab446e | pip | 26.1.2 | 1 |
| neilpeterson/ | 969af3cb8466 | pip | 26.1.2 | 1 |
| neilpeterson/ | 39ce9f92e899 | pip | 26.1.2 | 1 |
| netbirdio/ | 15a3aab9a345 | pip | 26.1.2 | 1 |
| netbirdio/ | 1b59e1c905c9 | pip | 26.1.2 | 1 |
| netbirdio/ | 332cc31f5f35 | pip | 26.1.2 | 1 |
| netbirdio/ | 88b5fb704a8c | pip | 26.1.2 | 1 |
| netboxcommunity/ | 3d652dca5351 | pip | 26.1.2 | 1 |
| netboxcommunity/ | 9bf83b350a89 | pip | 26.1.2 | 1 |
| networktocode/ | ed484336b1ad | pip | 26.1.2 | 1 |
| neuvector/ | 9e729010b7eb | pip | 26.1.2 | 1 |
| ngoduykhanh/ | 099371dd9ba6 | pip | 26.1.2 | 1 |
| ngoduykhanh/ | 9898a7cf37d2 | pip | 26.1.2 | 1 |
| nlmacamp/ | 5dbb8589f824 | pip | 26.1.2 | 1 |
| nousresearch/ | e0df6adebddf | python-pip | no fix listed | 1 |
| nyurik/ | e0553236e3eb | pip | 26.1.2 | 1 |
| octoprint/ | 106c26efcd8a | pip | 26.1.2 | 1 |
| octoprint/ | ea3bffae2470 | pip | 26.1.2 | 1 |
| odaniait/ | 3fff8a8570ec | pip | 26.1.2 | 1 |
| odavid/ | e7ab3bbc948e | pip | 26.1.2 | 1 |
| oled01/ | 05d3e398e675 | pip | 26.1.2 | 1 |
| omecproject/ | bcc5f19fd676 | pip python-pip | 26.1.2 no fix listed | 1 |
| omecproject/ | d109a8e57e71 | pip python-pip | 26.1.2 no fix listed | 1 |
| omkara25/ | 8327546c7aac | pip | 26.1.2 | 1 |
| omkara25/ | afff40172b6b | pip | 26.1.2 | 1 |
| omkara25/ | d62cba548580 | pip | 26.1.2 | 1 |
| onyxdotapp/ | 473fdffe4e67 | pip | 26.1.2 | 1 |
| opea/ | 25dd26d9cd09 | pip | 26.1.2 | 1 |
| opea/ | 38c51b791efa | pip | 26.1.2 | 1 |
| opea/ | 58f91683892d | pip | 26.1.2 | 1 |
| opea/ | e2436483b73d | pip | 26.1.2 | 1 |
| opea/ | 3eaa91849512 | pip | 26.1.2 | 1 |
| opea/ | 262c6048aab8 | pip | 26.1.2 | 1 |
| opea/ | f68bec6a1271 | pip | 26.1.2 | 1 |
| opea/ | 02f9e8fa5d71 | pip | 26.1.2 | 1 |
| opea/ | 249afad3d268 | pip | 26.1.2 | 1 |
| opea/ | 257ae94709e9 | pip | 26.1.2 | 1 |
| opea/ | fe08165d7770 | pip | 26.1.2 | 1 |
| openbas/ | a277796d9724 | pip python-pip | 26.1.2 no fix listed | 1 |
| opencsghq/ | 2f03fead54db | pip | 26.1.2 | 1 |
| opencsghq/ | 2cd29671a03e | pip | 26.1.2 | 1 |
| opencsghq/ | c36a5bac3cf0 | pip | 26.1.2 | 1 |