Bash and Zsh Script Vulnerability in Virtualenv by Python Packaging Authority
CVE-2026-102925
7.8HIGH
What is CVE-2026-102925?
Virtualenv, a tool for creating isolated Python environments, has a vulnerability that affects bash and zsh activation scripts. Prior to version 21.7.13, when the activation script is sourced, crafted environment paths could lead to code execution by exposing user privileges. The scripts improperly handled escape sequences, allowing shell metacharacters to be parsed as commands. This flaw is addressed in the latest release.
Affected Version(s)
virtualenv < 21.7.13
