CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2018-20225

highCVSS 7.8covered by 1 sourcefirst seen 2026-08-06

CSIRTS triage

vendor: pipproduct: pipSupply chainaffected: all versions
What
pip's --extra-index-url option allows installation of packages from unintended sources when a higher version number exists on a public index.
Who is affected
All pip users relying on private package indexes with the --extra-index-url flag.
Urgency
High severity (CVSS 7.8) supply chain risk; attackers can inject malicious packages of higher version numbers.
Action
Upgrade pip to a patched version that prioritizes private index packages correctly, or avoid --extra-index-url in favor of configuration-based index priority.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2018-20225

Get an email if CVE-2018-20225 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2018-20225

CVE.org record

Embed the live status

CVE-2018-20225 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2018-20225 status](https://www.csirts.com/badge/CVE-2018-20225)](https://www.csirts.com/cve/CVE-2018-20225)