{"id":"BIT-pip-2023-5752","summary":"Mercurial configuration injectable in repo revision when installing via pip","details":"When installing a package from a Mercurial VCS URL  (ie \"pip install \nhg+...\") with pip prior to v23.3, the specified Mercurial revision could\n be used to inject arbitrary configuration options to the \"hg clone\" \ncall (ie \"--config\"). Controlling the Mercurial configuration can modify\n how and which repository is installed. This vulnerability does not \naffect users who aren't installing from Mercurial.","modified":"2026-03-24T01:26:22.540221275Z","published":"2024-03-06T11:01:43.973Z","withdrawn":"2026-03-24T01:15:08.352859Z","database_specific":{"cpes":["cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*"],"severity":"Low"},"references":[{"type":"WEB","url":"https://github.com/pypa/pip/pull/12306"},{"type":"WEB","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YBSB3SUPQ3VIFYUMHPO3MEQI4BJAXKCZ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KFC2SPFG5FLCZBYY2K3T5MFW2D22NG6E/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/622OZXWG72ISQPLM5Y57YCVIMWHD4C3U/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/65UKKF5LBHEFDCUSPBHUN4IHYX7SRMHH/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FXUVMJM25PUAZRQZBF54OFVKTY3MINPW/"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5752"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html"}],"affected":[{"package":{"name":"pip","ecosystem":"Bitnami","purl":"pkg:bitnami/pip"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"23.3.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/pip/BIT-pip-2023-5752.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}],"schema_version":"1.7.3"}