virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influences --prompt, VIRTUAL
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pypa | virtualenv | < 21.7.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102925 | 7.8 HIGH | virtualenv bash and fish activation scripts execute commands embedded in paths |
| CVE-2026-102930 | 7.7 HIGH | virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use |
| CVE-2026-102938 | 5.8 MEDIUM | virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowi |
No comments yet