Python Security Update (MINDBREEZE42851)

ID: MINDBREEZE42851 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 5.3 Medium 
Status: Final 
First published: August 5, 2026 
CVEs: CVE-2026-3219, CVE-2026-6357 

Summary 

  • pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file 
  • pip self-update functionality can import newly installed modules after wheel installation 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.4 Release
  • Mindbreeze InSpire SaaS 26.4 Release