pip is vulnerable to Arbitrary Code Execution
60
Medium Risk
Affected versions of this package are affected by a design flaw when handling lazy imports that allow a malicious .whl file to overwrite critical modules, such as pip/_internal/self_outdated_check.py, during installation. When pip dynamically imports the modified module, the rogue code executes, enabling arbitrary code execution. An attacker could exploit this vulnerability to force systems to install untrusted packages or execute malicious code.
You are affected if you are using a version that falls within the vulnerable range.
pip is vulnerable to Arbitrary Code Execution in versions 24.1.0 - 24.3.1.
Upgrade the pip library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant