Bug 2544266 (CVE-2026-102938) - CVE-2026-102938 virtualenv: virtualenv: Arbitrary code execution via configuration injection in prompt values
Summary: CVE-2026-102938 virtualenv: virtualenv: Arbitrary code execution via configur...
Keywords:
Status: NEW
Alias: CVE-2026-102938
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-30 20:25 UTC by OSIDB Bzimport
Modified: 2026-09-30 20:32 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-30 20:25:59 UTC
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the last value for duplicate keys. An attacker who influences --prompt, VIRTUALENV_PROMPT, or configuration input can insert a recognized line boundary and additional keys, including home, causing consumers to use an attacker-selected base interpreter or corrupted environment metadata. The security impact requires prompt input from outside the operator's trust boundary; directly supplied prompt content primarily corrupts the operator's own environment. This issue is fixed in version 21.7.11.


Note You need to log in before you can comment on or make changes to this bug.