> An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index.
https://nvd.nist.gov/vuln/detail/cve-2018-20225
Because I'm sure the public wants to know.