Bug 2543654 (CVE-2026-102925)

Summary: CVE-2026-102925 virtualenv: virtualenv: Arbitrary code execution via crafted paths in activation scripts
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, anpicker, anthomas, aos-team-art-private, aprice, asdas, bparees, cmyers, dnakabaa, dpaolell, dschmidt, ehelms, gbenhaim, ggainey, hasun, ikhan, jdelft, jdobes, jfula, jlanda, jmitchel, jowilson, jpasqual, jsamir, jupierce, juwatts, jwong, kaycoth, kgaikwad, kshier, lcouzens, lgarciaa, mbiarnes, mdellweg, mhulan, niyer, nmoumoul, nyancey, oezr, omaciel, ometelka, orabin, osousa, pcreech, ppalepu, ppostler, prdhamdh, prwatson, ptisnovs, rbobbitt, rchan, rhel-process-autobot, sdawley, sghai, sidsharm, simaishi, smallamp, stcannon, suppawar, syedriko, tmalecek, ttakamiy, twaugh, vlaad, watson-tool-maintainers, xdharmai, xiaoxwan, yguenane, zzhou
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in virtualenv. The generated activation scripts for shells such as bash, zsh, and fish apply improper quoting to environment and library path variables. An attacker can exploit this by providing a crafted virtual environment path containing shell metacharacters. When an unsuspecting user sources the activation script, the embedded metacharacters are executed as shell commands, leading to arbitrary code execution with the privileges of that user.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-29 21:07:06 UTC
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish script, crafted Tcl or Tk library paths reach __TCL_LIBRARY__ or __TK_LIBRARY__. The surplus quotes can terminate the data-only quoted run and leave shell metacharacters parsed as commands when a user sources the activation script, allowing code execution with that user's privileges. This issue is fixed in version 21.7.13.