« List of all CVEs

CVE-2023-5752

Mercurial configuration injectable in repo revision when installing via pip

Published: 10/24/2023 Last updated: 2/13/2025 Reserved: 10/24/2023

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.

CNA assigner: PSF (28c92f92-d60d-412d-b760-e73465c3df22) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.5 Medium CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Opam packages affected (1)

catala

Products affected (1)

Product Vendor Version
pip Pip maintainers <= 1.14.7

References (14)

Credits (1)