Home

Description

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

PUBLISHED Reserved 2024-11-24 | Published 2024-11-24 | Updated 2024-11-24 | Assigner mitre

References

github.com/pypa/virtualenv/issues/2768

github.com/pypa/virtualenv/releases/tag/20.26.6

github.com/pypa/virtualenv/pull/2771

cve.org (CVE-2024-53899)

nvd.nist.gov (CVE-2024-53899)

Download JSON