Pypa / Virtualenv
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-102938 | virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection | MEDIUM | 5.8 | Sep 29, 2026 |
| CVE-2026-102937 | virtualenv: Command injection via --prompt in activate.bat (batch activator) | HIGH | 7.3 | Sep 29, 2026 |
| CVE-2026-102930 | virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use | HIGH | 7.7 | Sep 29, 2026 |
| CVE-2026-102925 | virtualenv bash and fish activation scripts execute commands embedded in paths | HIGH | 7.8 | Sep 29, 2026 |
| CVE-2026-22702 | virtualenv Has TOCTOU Vulnerabilities in Directory Creation | MEDIUM | 4.5 | Jan 10, 2026 |
Showing 1 to 5 of 5 CVEs