Medium severity6.5NVD Advisory· Published Jul 29, 2026· Updated Aug 20, 2026
CVE-2026-13346
CVE-2026-13346
Description
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.
This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running pip download with the --only-binary option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pipPyPI | < 26.2.0 | 26.2.0 |
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/python-pip&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/tensorflow-gpu-jupyterpkg:rpm/opensuse/python310&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-pip&distro=openSUSE%20Leap%2016.0
< 26.2-1.1+ 3 more
- (no CPE)range: < 26.2-1.1
- (no CPE)range: < 2.21.0-r8
- (no CPE)range: < 3.10.20-10.1
- (no CPE)range: < 25.0.1-160000.6.1
- Package: https://pypi.org/project/pip
Patches
Vulnerability mechanics
References
8- github.com/pypa/pip/pull/14110nvdIssue TrackingPatchWEB
- www.openwall.com/lists/oss-security/2026/07/29/7nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-qwm4-qh6w-59xrghsaADVISORY
- mail.python.org/archives/list/[email protected]/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/nvdMailing ListThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2026-13346ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-3721.yamlghsaWEB
- github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679ghsaWEB
- mail.python.org/archives/list/[email protected]/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQXghsaWEB
News mentions
0No linked articles in our index yet.