Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1 advisory

Loading
pip's fallback tar extraction doesn't check symbolic links point to extraction directory Moderate
CVE-2025-8869 was published for pip (pip) Sep 24, 2025
cai0duque Credited to cai0duque, bentasker, swils23, ichard26, and gcbirzan-plutoflume bentasker bentasker
swils23 swils23 ichard26 ichard26 gcbirzan-plutoflume gcbirzan-plutoflume
ProTip! Advisories are also available from the GraphQL API