Remote Code Execution Vulnerability in Virtualenv by PyPa
CVE-2026-102938

5.8MEDIUM

Key Information:

Vendor

Pypa

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102938?

A security vulnerability in Virtualenv allows attackers to manipulate prompt values and configuration inputs. Specifically, the function PyEnvCfg.write() improperly handles input, enabling an attacker to insert recognized line boundaries and additional keys. This can lead to the selection of a malicious interpreter or corrupt environment metadata. The threat primarily arises from untrusted prompt input sources, which can compromise the operator's environment. The issue has been rectified in Virtualenv version 21.7.11.

Affected Version(s)

virtualenv < 21.7.11

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.