Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-8869

Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/09/2025
Última modificación:
03/11/2025

Descripción

*** Pendiente de traducción *** When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn&amp;#39;t implement PEP 706.<br /> Note that upgrading pip to a "fixed" version for this vulnerability doesn&amp;#39;t fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706.<br /> <br /> Note that this is a vulnerability in pip&amp;#39;s fallback implementation of tar extraction for Python versions that don&amp;#39;t implement PEP 706<br /> and therefore are not secure to all vulnerabilities in the Python &amp;#39;tarfile&amp;#39; module. If you&amp;#39;re using a Python version that implements PEP 706<br /> then pip doesn&amp;#39;t use the "vulnerable" fallback code.<br /> <br /> Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python &gt;=3.9.17, &gt;=3.10.12, &gt;=3.11.4, or &gt;=3.12),<br /> applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice.