All 5 CVE vulnerabilities found in virtualenv, with AI-generated Chinese analysis, references, and POCs.
Vendor: pypa
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-102938 | virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection CWE-93 | 5.8 | Medium | 2026-09-29 |
| CVE-2026-102937 | virtualenv: Command injection via --prompt in activate.bat (batch activator) CWE-78 | 7.3 | High | 2026-09-29 |
| CVE-2026-102930 | virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use CWE-494 | 7.7 | High | 2026-09-29 |
| CVE-2026-102925 | virtualenv bash and fish activation scripts execute commands embedded in paths CWE-78 | 7.8 | High | 2026-09-29 |
| CVE-2026-22702 | virtualenv Has TOCTOU Vulnerabilities in Directory Creation CWE-59 | 4.5 | Medium | 2026-01-10 |
All 5 known CVE vulnerabilities affecting virtualenv with full Chinese analysis, references, and POCs where available.