{"id":"CLEANSTART-2026-OH23140","summary":"pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed o...","details":"Multiple security vulnerabilities affect the python3 package. pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. See references for individual vulnerability details.","modified":"2026-09-18T12:15:10.965778458Z","published":"2026-09-18T01:43:00.866976Z","withdrawn":"2026-09-18T11:59:01.768079Z","upstream":["CVE-2015-20107","CVE-2015-2104","CVE-2019-16056","CVE-2019-16935","CVE-2019-20907","CVE-2019-5010","CVE-2020-14422","CVE-2020-8315","CVE-2020-8492","CVE-2021-23336","CVE-2021-29921","CVE-2021-3177","CVE-2021-3426","CVE-2022-45061","CVE-2023-27043","CVE-2023-40217","CVE-2024-12254","CVE-2024-12718","CVE-2024-4032","CVE-2024-6232","CVE-2024-6923","CVE-2024-7592","CVE-2024-8088","CVE-2024-9287","CVE-2025-0938","CVE-2025-24049","CVE-2025-4138","CVE-2025-4330","CVE-2025-4516","CVE-2025-4517","CVE-2025-59375","CVE-2026-1703","CVE-2026-3219","CVE-2026-6357","CVE-2026-8643"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-OH23140.json"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2015-20107"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2015-2104"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2019-16056"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2019-16935"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2019-20907"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2019-5010"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-14422"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-8315"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-8492"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2021-23336"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2021-29921"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2021-3177"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2021-3426"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2022-45061"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2023-27043"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2023-40217"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-12254"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-12718"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-4032"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-6232"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-6923"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-7592"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-8088"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-9287"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-0938"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-24049"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-4138"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-4330"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-4516"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-4517"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-59375"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-1703"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-3219"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-6357"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-8643"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-20107"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-2104"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16056"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16935"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5010"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-14422"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8315"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8492"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29921"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3426"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-45061"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27043"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40217"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12254"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12718"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-4032"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6232"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6923"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-7592"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8088"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9287"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0938"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24049"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4138"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4330"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4516"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4517"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59375"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1703"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3219"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6357"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8643"}],"affected":[{"package":{"name":"python3","ecosystem":"CleanStart"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.9.5-r0"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-OH23140.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}