pip is vulnerable to Arbitrary Code Execution
60
Medium Risk
Affected versions of this package are affected by a design flaw when handling lazy imports that allow a malicious .whl file to overwrite critical modules, such as pip/_internal/self_outdated_check.py, during installation. When pip dynamically imports the modified module, the rogue code executes, enabling arbitrary code execution. An attacker could exploit this vulnerability to force systems to install untrusted packages or execute malicious code.
You are affected if you are using a version that falls within the vulnerable range.
pip is vulnerable to Arbitrary Code Execution in versions 24.1.0 - 24.3.1.
Upgrade the pip library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant