CVE-2026-102930
Received Received - Intake

Path Traversal in virtualenv Python Environment Tool

Vulnerability report for CVE-2026-102930, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an authoritative digest equivalent to the embedded wheels' BUNDLE_SHA256 verification. A compromised index, stale mirror, or intercepted TLS connection can substitute a different wheel under the requested distribution, version, and filename, after which virtualenv caches and seeds the attacker-controlled wheel into subsequently created environments. The verification applies to the default PyPI path and is intentionally skipped when PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, or PIP_INDEX configures a custom index that may legitimately publish rebuilt wheels. This issue is fixed in version 21.7.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in virtualenv before version 21.7.12 allows an attacker to substitute a malicious wheel file for a legitimate one during the download process. This happens because the tool does not verify the downloaded files against an authoritative digest like BUNDLE_SHA256. As a result, compromised wheels can be cached and used in future virtual environments.

Impact Analysis

If exploited, this vulnerability could allow an attacker to execute arbitrary code in your Python environment. This might lead to data breaches, unauthorized access, or system compromise. Users creating virtual environments with vulnerable versions are at risk if they rely on untrusted package indexes.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized data access or breaches. Organizations must ensure their Python environments are secure to protect sensitive data and meet regulatory requirements.

Mitigation Strategies

Upgrade virtualenv to version 21.7.12 or later to address the vulnerability in download_wheel().

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102930. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart