When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-python-pip-wheelamazon-linux-ami-2-upgrade-python2-pipamazon-linux-ami-2-upgrade-python3-pip | Dec 5, 2023 | Oct 25, 2023 | |
| Debian | debian-upgrade-python-pip | May 15, 2025 | Oct 25, 2023 | |
| Dell Powerstore Dsa2024462 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Nov 20, 2024 | |
| Dell Powerstore Dsa2024497 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Dec 19, 2024 | |
| Dell Powerstore Dsa2025050 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Jan 28, 2025 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-python-pip | Jan 20, 2025 | Oct 25, 2023 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 25, 2023 |
| Suse | — | suse-upgrade-python-pipsuse-upgrade-python3-pipsuse-upgrade-python311-pipsuse-upgrade-python36-pip | Dec 29, 2023 | Oct 25, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub