Bash and Zsh Script Vulnerability in Virtualenv by Python Packaging Authority
CVE-2026-102925

7.8HIGH

Key Information:

Vendor

Pypa

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102925?

Virtualenv, a tool for creating isolated Python environments, has a vulnerability that affects bash and zsh activation scripts. Prior to version 21.7.13, when the activation script is sourced, crafted environment paths could lead to code execution by exposing user privileges. The scripts improperly handled escape sequences, allowing shell metacharacters to be parsed as commands. This flaw is addressed in the latest release.

Affected Version(s)

virtualenv < 21.7.13

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.