virtualenv allows command injection through activation scripts for a virtual environment
High severity
GitHub Reviewed
Published
Nov 24, 2024
to the GitHub Advisory Database
•
Updated Jan 13, 2025
Description
Published by the National Vulnerability Database
Nov 24, 2024
Published to the GitHub Advisory Database
Nov 24, 2024
Reviewed
Jan 13, 2025
Last updated
Jan 13, 2025
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
References