PT-2025-39265 · Python+3 · Python 3.12+6

CVE-2025-8869

·

Published

2025-01-01

·

Updated

2026-08-25

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions pip (affected versions not specified)
Description An issue exists in pip where it may not properly check symbolic links when extracting tar archives if the tarfile module does not implement PEP 706. This can occur when using Python versions that do not implement PEP 706, and pip uses its fallback implementation for tar extraction. Upgrading pip to a fixed version does not address all known issues remediated by using a Python version that implements PEP 706. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python versions 3.9.17 and later, 3.10.12 and later, 3.11.4 and later, or 3.12 and later), applying the associated patch, or inspecting source distributions before installation.
Recommendations Upgrade to a version of pip that includes the fix. Upgrade to Python version 3.9.17 or later. Upgrade to Python version 3.10.12 or later. Upgrade to Python version 3.11.4 or later. Upgrade to Python version 3.12 or later. Apply the associated patch. Inspect source distributions before installation.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-67788
BDU:2025-13251
BIT-PIP-2025-8869
CLEANSTART-2026-DD95169
CLEANSTART-2026-NN42198
CLEANSTART-2026-NR60332
CLEANSTART-2026-SA70432
CLEANSTART-2026-UC45646
CLEANSTART-2026-YC81398
CLEANSTART-2026-ZO99127
CVE-2025-8869
DLA-4348-1
ECHO-FFE1-1D3C-D9BC
GHSA-4XH5-X5GV-QWPH
OESA-2025-2714
OESA-2025-2741
OESA-2025-2794
PYSEC-2026-1795

Affected Products

Debian
Python 3.10.12
Python 3.11.4
Python 3.12
Python 3.9.17
Red Os
Pip