CVE-2026-102937High· 7.3▾ Twilightvirtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influ…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax. When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102925High· 7.8virtualenv is a tool for creating isolated virtual python environments
CVE-2026-102938Medium· 5.8virtualenv is a tool for creating isolated virtual python environments
CVE-2026-102930High· 7.7virtualenv is a tool for creating isolated virtual python environments
CVE-2024-53899High· 8.4virtualenv allows command injection through activation scripts for a virtual environment
CVE-2026-22702Medium· 4.5virtualenv Has TOCTOU Vulnerabilities in Directory Creation
CVE-2025-9580Medium· 6.3A security vulnerability has been detected in LB-LINK BL-X26 1.2.8