CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2018-20225: An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and t

highCVSS 7.8CVE-2018-20225

CSIRTS triage

vendor: pipproduct: pipSupply chainaffected: all versions
What
pip's --extra-index-url option allows installation of packages from unintended sources when a higher version number exists on a public index.
Who is affected
All pip users relying on private package indexes with the --extra-index-url flag.
Urgency
High severity (CVSS 7.8) supply chain risk; attackers can inject malicious packages of higher version numbers.
Action
Upgrade pip to a patched version that prioritizes private index packages correctly, or avoid --extra-index-url in favor of configuration-based index priority.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch pip

Get an email when a new pip advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
high — CVSS 7.8
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-20225

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2018-20225coverage & exploitation statusNVD · CVE.org

Recent advisories for pip

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center