virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh scrip
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pypa | virtualenv | < 21.7.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102930 | 7.7 HIGH | virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use |
| CVE-2026-102937 | 7.3 HIGH | virtualenv: Command injection via --prompt in activate.bat (batch activator) |
| CVE-2026-102938 | 5.8 MEDIUM | virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowi |
No comments yet