PT-2026-105774 · Pypi · Virtualenv
Publicado
2026-09-18
·
Atualizado
2026-09-18
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
The generated
activate (bash/zsh) and activate.fish scripts interpolate a
shlex.quote-ed value into a position that quotes it a second time. The extra
quotes terminate the quoted run early and leave part of the value parsed as
shell code, so a path containing shell metacharacters runs commands when a user
sources the activation script.activate is affected through the virtual environment's own path, on the branch
that reports a relocated environment (Virtual environment directory VIRTUAL ENV does not exist!). For a destination named x'$(id)'y,
shlex.quote emits 'x'"'"'$(id)'"'"'y'; the inner " closes the enclosing
double quote and $(id) is left unquoted. This branch runs whenever the
recorded path is absent, which is the normal case for a virtual environment
copied or distributed to another machine.activate.fish is affected through the interpreter's Tcl/Tk library paths
(set -gx TCL LIBRARY ' TCL LIBRARY '). The rendered line becomes
''/tcl/(cmd)/lib'', and fish expands the (cmd) left between the adjacent
quoted runs. The same doubling splits a path containing a space into two list
elements, corrupting TCL LIBRARY and TK LIBRARY.This is the same defect class as GHSA-x78j-v8h9-3j2q, which covered
activate.bat.Fixed in 21.7.13 by moving the placeholders outside the surrounding quotes, so
each value keeps only the quoting
shlex.quote applied.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Virtualenv