/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-5752

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-5752

CGA ID

CGA-69m5-9w6x-qr3f

Severity

3.3

Low

CVSS V3

Description

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs