© 2025-2026 PySpect
First version without a known vulnerability: 26.2
pip would incorrectly handle doubly-encoded package URLs from indexes
Fixed in: 26.2.0, 26.2
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Fixed in: 26.1.2
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Fixed in: 26.1
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Fixed in: 26.1
pip Path Traversal vulnerability
Fixed in: 26.0
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
Fixed in: 25.3
Command Injection in pip when used with Mercurial
Fixed in: 23.3
Improper Authentication in pip
Fixed in: 1.5
Improper Link Resolution Before File Access in pip
Fixed in: 1.3
pip lack of randomness in build directory
Fixed in: 6.0
Improper Input Validation in pip
Fixed in: 1.3
Improper Input Validation in pip
Fixed in: 21.1
Path Traversal in pip
Fixed in: 19.2, a4c735b14a62f9cb864533808ac63936704f2ace