virtualenv
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting virtualenvpage 1 of 1
- CVE-2011-4617LOWCVSS v2 1.2EG 1.2fixed in 1.52011-12-31
vulnerable: 0.8 ... 1.4rc1 (27 versions)
virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.
- CVE-2024-53899HIGHCVSS 7.8EG 7.8fixed in 20.26.62024-11-24
vulnerable: 0.8 ... 20.9.0 (222 versions)
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
- CVE-2026-102925HIGHCVSS 7.8EG 7.8fixed in 21.7.132026-09-29
vulnerable: 0.8 ... 21.7.9 (282 versions)
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In t…
- CVE-2026-102930HIGHCVSS 7.7EG 7.7fixed in 21.7.122026-09-29
vulnerable: 0.8 ... 21.7.9 (281 versions)
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an…
- CVE-2026-102937HIGHCVSS 7.3EG 7.3fixed in 21.7.122026-09-29
vulnerable: 0.8 ... 21.7.9 (281 versions)
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influen…
- CVE-2026-102938MEDIUMCVSS 5.8EG 5.8fixed in 21.7.112026-09-29
vulnerable: 0.8 ... 21.7.9 (280 versions)
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlin…
- CVE-2026-22702MEDIUMCVSS 4.5EG 4.5fixed in 20.36.12026-01-10
vulnerable: 0.8 ... 20.9.0 (245 versions)
virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory creation…
Check whether virtualenv is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for virtualenv CVEs against the assets you own.
Book a Demo →