PYSEC-2026-3721
Dashboard / Vulnerabilities / PYSEC-2026-3721
PYSEC-2026-3721
Summary:
Details: pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.
References: http://www.openwall.com/lists/oss-security/2026/07/29/7, https://mail.python.org/archives/list/[email protected]/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/, https://github.com/pypa/pip/pull/14110, https://github.com/advisories/GHSA-qwm4-qh6w-59xr
Affected packages
Package
Name: pip
Purl: pkg:pypi/pip
Affected ranges
Type: ECOSYSTEM
Events:
