Bug 2543654 (CVE-2026-102925)
| Summary: | CVE-2026-102925 virtualenv: virtualenv: Arbitrary code execution via crafted paths in activation scripts | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akhatavk, anpicker, anthomas, aos-team-art-private, aprice, asdas, bparees, cmyers, dnakabaa, dpaolell, dschmidt, ehelms, gbenhaim, ggainey, hasun, ikhan, jdelft, jdobes, jfula, jlanda, jmitchel, jowilson, jpasqual, jsamir, jupierce, juwatts, jwong, kaycoth, kgaikwad, kshier, lcouzens, lgarciaa, mbiarnes, mdellweg, mhulan, niyer, nmoumoul, nyancey, oezr, omaciel, ometelka, orabin, osousa, pcreech, ppalepu, ppostler, prdhamdh, prwatson, ptisnovs, rbobbitt, rchan, rhel-process-autobot, sdawley, sghai, sidsharm, simaishi, smallamp, stcannon, suppawar, syedriko, tmalecek, ttakamiy, twaugh, vlaad, watson-tool-maintainers, xdharmai, xiaoxwan, yguenane, zzhou |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in virtualenv. The generated activation scripts for shells such as bash, zsh, and fish apply improper quoting to environment and library path variables. An attacker can exploit this by providing a crafted virtual environment path containing shell metacharacters. When an unsuspecting user sources the activation script, the embedded metacharacters are executed as shell commands, leading to arbitrary code execution with the privileges of that user.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-29 21:07:06 UTC
|