CVE Explorer
CVE-2025-8869
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706.
Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706.
Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706
and therefore are not secure to all vuln
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://pypi.org/project/pip","defaultStatus":"unaffected","packageName":"pip","product":"pip","repo":"https://github.com/pypa/pip","vendor":"Python Packaging Authority","versions":[{"lessThan":"25.3","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e62f43f5a1767163aa39e5b0527904b6f32eed1e9c045957685f871e24e60322 · sha256:09cf9e0d2a77a1c2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":5.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e62f43f5a1767163aa39e5b0527904b6f32eed1e9c045957685f871e24e60322 · sha256:09cf9e0d2a77a1c2… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"description":"CWE-noinfo Not enough information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e62f43f5a1767163aa39e5b0527904b6f32eed1e9c045957685f871e24e60322 · sha256:09cf9e0d2a77a1c2… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["patch"],"url":"https://github.com/pypa/pip/pull/13550"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e62f43f5a1767163aa39e5b0527904b6f32eed1e9c045957685f871e24e60322 · sha256:09cf9e0d2a77a1c2… · /containers/cna/references/0
{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e62f43f5a1767163aa39e5b0527904b6f32eed1e9c045957685f871e24e60322 · sha256:09cf9e0d2a77a1c2… · /containers/adp/1/references/0
{"tags":["vendor-advisory"],"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/IF5A3GCJY3VH7BVHJKOWOJFKTW7VFQEN/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e62f43f5a1767163aa39e5b0527904b6f32eed1e9c045957685f871e24e60322 · sha256:09cf9e0d2a77a1c2… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.