CVE-2018-20225 - CVE House
Back to Database
Status published Unknown CVE-2018-20225

An issue was discovered in pip (all versions) because it...

Vulnerability Description

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-20225

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

pip
Vulnerable Versions:
Unknown

Timeline

Official Publish: May 8th, 2020
Last Modified: April 15th, 2026
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.