CVE-2026-102937

HIGH CVSS 4.0: 7.3
Updated Sep 30, 2026
Pypa
Parameter Value
CVSS 7.3 (HIGH)
Fixed In 21.7.12
Type CWE-78 (OS Command Injection)
Vendor Pypa
Public PoC No

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax.

When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products

pypa:virtualenv