{"id":"CVE-2026-22702","aliases":["GHSA-597g-3phw-6986","BIT-virtualenv-2026-22702","PYSEC-2026-2009"],"title":"virtualenv Has TOCTOU Vulnerabilities in Directory Creation","summary":"virtualenv Has TOCTOU Vulnerabilities in Directory Creation","severity":"medium","cvss":4.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","vendor":"virtualenv","product":"virtualenv","ecosystem":"pip","affected":["virtualenv < 20.36.1"],"patched":["virtualenv 20.36.1"],"published":"2026-01-13","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:32.732715893Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-597g-3phw-6986","references":[{"url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-597g-3phw-6986"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22702"},{"url":"https://github.com/pypa/virtualenv/pull/3013"},{"url":"https://github.com/pypa/virtualenv/commit/dec4cec5d16edaf83a00a658f32d1e032661cebc"},{"url":"https://github.com/pypa/virtualenv"}],"tags":["osv","pip"],"epss":0.00098,"epssPercentile":0.00878,"ingestedAt":"2026-07-08T18:25:45.829Z","slug":"CVE-2026-22702","body":"## Overview\n\n## Impact\n\nTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in `virtualenv` allow local attackers to perform symlink-based attacks on directory creation operations. An attacker with local access can exploit a race condition between directory existence checks and creation to redirect virtualenv's app_data and lock file operations to attacker-controlled locations.\n\n**Affected versions:** All versions up to and including 20.36.1\n\n**Affected users:** Any user running `virtualenv` on multi-user systems where untrusted local users have filesystem access to shared temporary directories or where `VIRTUALENV_OVERRIDE_APP_DATA` points to a user-writable location.\n\n**Attack scenarios:**\n- Cache poisoning: Attacker corrupts wheels or Python metadata in the cache\n- Information disclosure: Attacker reads sensitive cached data or metadata\n- Lock bypass: Attacker controls lock file semantics to cause concurrent access violations\n- Denial of service: Lock starvation preventing virtualenv operations\n\n## Patches\n\nThe vulnerability has been patched by replacing check-then-act patterns with atomic `os.makedirs(..., exist_ok=True)` operations.\n\n**Fixed in:** PR #3013\n\n**Versions with the fix:** 20.36.2 and later\n\nUsers should upgrade to version 20.36.2 or later.\n\n## Workarounds\n\nIf you cannot upgrade immediately:\n\n1. Ensure `VIRTUALENV_OVERRIDE_APP_DATA` points to a directory owned by the current user with restricted permissions (mode 0700)\n2. Avoid running `virtualenv` in shared temporary directories where other users have write access\n3. Use separate user accounts for different projects to isolate app_data directories\n\n## References\n\n- GitHub PR: https://github.com/pypa/virtualenv/pull/3013\n- Vulnerability reported by: @tsigouris007\n- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (TOCTOU)\n- CWE-59: Improper Link Resolution Before File Access\n\n## Affected packages\n\n- `virtualenv < 20.36.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `virtualenv 20.36.1`","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":24.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}