Junglewise Threat Intelligence

CVE-2026-6357: PYSEC-2026-2876 - pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

CVE-2026-6357 · Severity: medium · CVSS 4 · Published 2026-07-13

Technologies: pip (PyPI). Vendors: PyPI.

Executive brief

pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

Affected products

  • PyPI pip

Related threats