Appsecure logo

CVE-2023-5752: Medium Vulnerability in pypa pip

A medium-severity vulnerability in pypa pip allows for arbitrary configuration injection during package installation from a Mercurial VCS URL. Organizations should address this issue promptly to mitigate potential integrity risks.

MEDIUMCVSS 5.5 · Published October 25, 2023

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2023-5752 is a medium-severity vulnerability affecting the pypa pip package manager. When installing a package from a Mercurial VCS URL (i.e., "pip install hg+...") using pip versions prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options into the "hg clone" call (i.e., "--config"). This vulnerability allows attackers to control the Mercurial configuration, potentially altering how and which repository is installed. Particularly, it does not affect users who are not installing from Mercurial.

The severity of this vulnerability is classified as medium with a CVSS score of 5.5. The risk to organizations includes potential integrity impact, as attackers could modify the installed repository by injecting malicious configurations. Given the nature of the vulnerability, organizations using pip for package installations should prioritize addressing this issue.

Currently, there are no known exploits or public proof of concepts (PoCs) associated with this vulnerability. Organizations should still remain vigilant as the potential for exploitation exists. Urgency for remediation is classified as moderate; organizations should schedule remediation in their patch cycle.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.