AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-20225

HIGH · CVSS 7.8 EPSS 1.74% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-05-08 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-20225
Severity
HIGH
CVSS
7.8
EPSS
1.74%

Original NVD Description

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

Related CVEs

Other vulnerabilities affecting the same vendor(s)