CVE-2026-102925
Received Received - Intake

Code Execution in Virtualenv Activation Scripts

Vulnerability report for CVE-2026-102925, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish script, crafted Tcl or Tk library paths reach __TCL_LIBRARY__ or __TK_LIBRARY__. The surplus quotes can terminate the data-only quoted run and leave shell metacharacters parsed as commands when a user sources the activation script, allowing code execution with that user's privileges. This issue is fixed in version 21.7.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects virtualenv versions before 21.7.13. When creating virtual environments, the activation scripts (bash, zsh, fish) improperly handle escaped paths. A crafted path in the virtual environment or related libraries can bypass security checks, allowing shell metacharacters to execute arbitrary commands when the script is sourced. This leads to code execution with the user's privileges.

Detection Guidance

Check the version of virtualenv installed on your system using the command: virtualenv --version. If the version is below 21.7.13, the system is vulnerable.

Impact Analysis

If you use an affected virtualenv version, an attacker could trick you into activating a malicious virtual environment. This could allow them to run arbitrary code on your system with your user permissions, potentially stealing data or installing malware.

Mitigation Strategies

Upgrade virtualenv to version 21.7.13 or later using pip: pip install --upgrade virtualenv. Avoid using virtual environments with untrusted paths or directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102925. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart