CVE-2026-8643
HighAdvisory
Published 1 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.0
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,282
- of 17,790 indexed, latest versions
- Container images
- 1,231
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Carried by container images the latest versions of 1,282 of 17,790 indexed charts deploy, on 1,231 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pippypi | 1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more | 26.1.2 | 1,224 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 more | no fix listed | 141 |
- OSV records
- GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
- Also known as
- PYSEC-2026-196
Charts affected
1,282 by stars
Container images carrying it
1,231 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| tomsquest/ | 4759cc353a1d | pip | 26.1.2 | 1 |
| tomsquest/ | a594c624c5a6 | pip | 26.1.2 | 1 |
| treskon/ | a475d80e4ecf | pip | 26.1.2 | 1 |
| trungkien210493/ | 2cc8c3763c4c | pip | 26.1.2 | 1 |
| tussanakorndev/ | 216fdadadf9a | pip | 26.1.2 | 1 |
| tykling/ | cd6d650c01c1 | pip | 26.1.2 | 1 |
| ubcctlt/ | cbbbbc8ae16b | pip | 26.1.2 | 1 |
| vabene1111/ | 0f8d061895e9 | pip | 26.1.2 | 1 |
| vabene1111/ | ec4e9e2905b0 | pip | 26.1.2 | 1 |
| vcnngr/ | 1a849a997b6d | pip | 26.1.2 | 1 |
| vcnngr/ | 30f1f05e57a6 | pip | 26.1.2 | 1 |
| veecode/ | a72cf5cb47b8 | pip | 26.1.2 | 1 |
| viadee/ | 2e27e3b3ee56 | pip | 26.1.2 | 1 |
| voltha/ | c4e41e92f046 | pip python-pip | 26.1.2 no fix listed | 1 |
| voltha/ | 37f80524c207 | pip python-pip | 26.1.2 no fix listed | 1 |
| voltha/ | 9ee8c1f4428c | pip python-pip | 26.1.2 no fix listed | 1 |
| voltha/ | 655c3048a602 | pip python-pip | 26.1.2 no fix listed | 1 |
| voltha/ | ff596b62de59 | pip python-pip | 26.1.2 no fix listed | 1 |
| wallarm/ | f1cb26db1f5b | pip python-pip | 26.1.2 no fix listed | 1 |
| wallarm/ | c527865df85d | pip | 26.1.2 | 1 |
| wazuh/ | 1da5c38c6a78 | pip | 26.1.2 | 1 |
| wazuh/ | 21994f40e0da | pip | 26.1.2 | 1 |
| wazuh/ | 5a065930682d | pip | 26.1.2 | 1 |
| wazuh/ | f09282d281f6 | pip | 26.1.2 | 1 |
| weblate/ | 82848df56ecd | pip | 26.1.2 | 1 |
| wiktorn/ | 9bb5f4a9b54c | pip python-pip | 26.1.2 no fix listed | 1 |
| wiremind/ | 4dea42c8166c | pip | 26.1.2 | 1 |
| witcherek7/ | 42a744f29ac0 | pip | 26.1.2 | 1 |
| xeladock/ | 4baf531453f1 | pip python-pip | 26.1.2 no fix listed | 1 |
| ybucci/ | 8d27ad8b5f73 | pip | 26.1.2 | 1 |
| ybucci/ | f1fcc7c8d9fd | pip | 26.1.2 | 1 |
| ygqygq2/ | 54f30def1558 | pip | 26.1.2 | 1 |
| youssef11gaber10/ | 96bce8b8b5a7 | pip | 26.1.2 | 1 |
| youssef11gaber10/ | 9c727fcfde76 | pip | 26.1.2 | 1 |
| yugabytedb/ | 3926eedf0ff4 | pip | 26.1.2 | 1 |
| yugabytedb/ | de2e00278645 | pip | 26.1.2 | 1 |
| yuzutech/ | 7c1917c66d96 | pip | 26.1.2 | 1 |
| zepai/ | 6ab0ee79926b | pip | 26.1.2 | 1 |
| zohardocker12/ | b86d60dbb68d | pip | 26.1.2 | 1 |
| zurdi15/ | 2db88fe44c89 | pip | 26.1.2 | 1 |
| gcr.io/ | 25d6975951f1 | pip | 26.1.2 | 1 |
| gcr.io/ | 360130ab5850 | pip | 26.1.2 | 1 |
| gcr.io/ | 5f60c4988859 | pip | 26.1.2 | 1 |
| gcr.io/ | a2259b098b13 | pip | 26.1.2 | 1 |
| gcr.io/ | a461dc5cb96a | pip | 26.1.2 | 1 |
| gcr.io/ | 9bcfd2abc361 | pip | 26.1.2 | 1 |
| gcr.io/ | ec3ae9f6df47 | pip | 26.1.2 | 1 |
| gcr.io/ | a534a3170d03 | pip | 26.1.2 | 1 |
| ghcr.io/ | bd6f22f7db0a | pip | 26.1.2 | 1 |
| ghcr.io/ | 18a81afcb249 | pip | 26.1.2 | 1 |