Python Security Update (MINDBREEZE42851)
ID: MINDBREEZE42851
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: 5.3 Medium
Status: Final
First published: August 5, 2026
CVEs: CVE-2026-3219, CVE-2026-6357
Summary
- pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file
- pip self-update functionality can import newly installed modules after wheel installation
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.4 Release
- Mindbreeze InSpire SaaS 26.4 Release