CVE-2026-102925
Last modified
CVE-2026-102925 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context.
Description
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish script, crafted Tcl or Tk library paths reach __TCL_LIBRARY__ or __TK_LIBRARY__. The surplus quotes can terminate the data-only quoted run and leave shell metacharacters parsed as commands when a user sources the activation script, allowing code execution with that user's privileges. This issue is fixed in version 21.7.13.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| pypa | virtualenv | < 21.7.13 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-102925?
How severe is CVE-2026-102925?
How do I fix CVE-2026-102925?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10289A security flaw has been discovered in code-projects Hotel a…4.3
- CVE-2026-1029IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2…5.4
- CVE-2026-10290A weakness has been identified in code-projects Hotel and To…7.3
- CVE-2026-102904JupyterLab is an extensible environment for interactive and …5.4
- CVE-2026-10291A security vulnerability has been detected in Enderfga claw-…5.3
- CVE-2026-10292A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3…8.8
- CVE-2026-10293A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306…8.8
- CVE-2026-102930virtualenv is a tool for creating isolated virtual python en…7.7
- CVE-2026-102937virtualenv is a tool for creating isolated virtual python en…7.3
- CVE-2026-102938virtualenv is a tool for creating isolated virtual python en…5.8
- CVE-2026-10294A vulnerability has been found in PackageKit up to 1.3.5. Af…4.3
- CVE-2026-10295A vulnerability was found in SourceCodester Customer Review …3.3
Are you affected by CVE-2026-102925?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
