MEDIUM 5.5 PyPI
Command Injection in pip when used with Mercurial
GHSA-mq26-g339-26xf · CVE-2023-5752 · PYSEC-2023-228
Published · Modified
Description
When installing a package from a Mercurial VCS URL, e.g. pip install hg+..., with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the hg clone call (e.g. --config). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-5752
- WEB https://github.com/pypa/pip/pull/12306
- WEB https://github.com/pypa/pip/commit/389cb799d0da9a840749fcd14878928467ed49b4
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2023-228.yaml
- PACKAGE https://github.com/pypa/pip
- WEB https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/622OZXWG72ISQPLM5Y57YCVIMWHD4C3U
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/65UKKF5LBHEFDCUSPBHUN4IHYX7SRMHH
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FXUVMJM25PUAZRQZBF54OFVKTY3MINPW
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KFC2SPFG5FLCZBYY2K3T5MFW2D22NG6E
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YBSB3SUPQ3VIFYUMHPO3MEQI4BJAXKCZ
- WEB https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL
Ready to move
Start Securing
Free, no credit card | First findings in minutes