CVE-2023-5752

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
25/10/2023
Last modified:
13/02/2025

Description

When installing a package from a Mercurial VCS URL (ie "pip install <br /> hg+...") with pip prior to v23.3, the specified Mercurial revision could<br /> be used to inject arbitrary configuration options to the "hg clone" <br /> call (ie "--config"). Controlling the Mercurial configuration can modify<br /> how and which repository is installed. This vulnerability does not <br /> affect users who aren&amp;#39;t installing from Mercurial.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:* 23.3 (excluding)


References to Advisories, Solutions, and Tools