GHSA-qwm4-qh6w-59xr
Dashboard / Vulnerabilities / GHSA-qwm4-qh6w-59xr
GHSA-qwm4-qh6w-59xr
Summary: pip would incorrectly handle doubly-encoded package URLs from indexes
Details: pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-13346, https://github.com/pypa/pip/pull/14110, https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679, https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-3721.yaml, https://github.com/pypa/pip, https://mail.python.org/archives/list/[email protected]/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX, http://www.openwall.com/lists/oss-security/2026/07/29/7
Affected packages
Package
Name: pip
Purl: pkg:pypi/pip
Affected ranges
Type: ECOSYSTEM
Events:
