virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pypa | virtualenv | < 21.7.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102925 | 7.8 HIGH | virtualenv bash and fish activation scripts execute commands embedded in paths |
| CVE-2026-102930 | 7.7 HIGH | virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use |
| CVE-2026-102937 | 7.3 HIGH | virtualenv: Command injection via --prompt in activate.bat (batch activator) |
No comments yet