PT-2026-102926 · Pypi · Virtualenv

·

CVE-2026-102938

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

5.8

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions virtualenv versions prior to 21.7.11
Description The PyEnvCfg.write() function writes prompt values verbatim to the line-oriented pyvenv.cfg format, while PyEnvCfg. read values() parses the file using str.splitlines() and accepts the last value for duplicate keys. An attacker who can influence the --prompt argument, the VIRTUALENV PROMPT variable, or configuration input can insert a line boundary and additional keys, such as home. This can lead to consumers using an attacker-selected base interpreter or corrupted environment metadata. This issue requires prompt input from outside the operator's trust boundary.
Recommendations Update virtualenv to version 21.7.11.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102938
GHSA-9H9J-4VRJ-GF7G

Affected Products

Virtualenv