CVE-2018-20225: An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and t
CSIRTS triage
- What
- pip's --extra-index-url option allows installation of packages from unintended sources when a higher version number exists on a public index.
- Who is affected
- All pip users relying on private package indexes with the --extra-index-url flag.
- Urgency
- High severity (CVSS 7.8) supply chain risk; attackers can inject malicious packages of higher version numbers.
- Action
- Upgrade pip to a patched version that prioritizes private index packages correctly, or avoid --extra-index-url in favor of configuration-based index priority.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch pip
Get an email when a new pip advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-20225
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2018-202251.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2018-20225 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for pip
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-76245: stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in f…nvd · 2026-08-19
- high[NEW] [high] Red Hat Enterprise Linux (python-pip): Vulnerability allows code executioncert-bund · 2026-08-19
- lowCVE-2026-74870: openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where th…nvd · 2026-08-17
- unknownCVE-2026-73627: JupyterLab (pip package 'jupyterlab') versions >=4.1.0, =4.6.0,<=4.6.1 contain a plugin manage…nvd · 2026-08-13
- unknownCVE-2026-13346: pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be…nvd · 2026-07-29
- highCVE-2026-61437: PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loadin…nvd · 2026-07-10
More from Microsoft Security Response Center
- lowCVE-2026-14673: PostgreSQL amcheck does not clear untrusted search path2026-08-11
- criticalCVE-2026-69836: Microsoft Entra ID Remote Code Execution Vulnerability2026-08-11
- mediumCVE-2026-53792: rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block2026-08-11
- highCVE-2026-70347: Windows Installer Elevation of Privilege Vulnerability2026-08-11
- highCVE-2026-64909: Microsoft Office Remote Code Execution Vulnerability2026-08-11