Critical
Low
Medium
CVE-2025-8869
Overview
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version ...
Critical
Low
Medium
No items found.