Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x78j-v8h9-3j2q | virtualenv: Command injection via --prompt in activate.bat (batch activator) |
Sat, 03 Oct 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 02 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pypa
Pypa virtualenv Python Python virtualenv |
|
| Vendors & Products |
Pypa
Pypa virtualenv Python Python virtualenv |
Tue, 29 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax. When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12. | |
| Title | virtualenv: Command injection via --prompt in activate.bat (batch activator) | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-02T12:28:15.446Z
Reserved: 2026-09-29T20:24:43.340Z
Link: CVE-2026-102937
Updated: 2026-10-02T12:28:08.381Z
Status : Awaiting Analysis
Published: 2026-09-29T21:17:18.893
Modified: 2026-10-02T13:17:35.440
Link: CVE-2026-102937
OpenCVE Enrichment
Updated: 2026-09-30T20:35:31Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Github GHSA