CVE-2026-102937
virtualenv: Command injection via --prompt in activate.bat (batch activator)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax. When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12.
| CWE | CWE-78 |
| Vendor | pypa |
| Product | virtualenv |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for pypa virtualenv
Be the first to know when new unknown vulnerabilities affecting pypa virtualenv are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
pypa / virtualenv
< 21.7.12
References
github.com: https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q github.com: https://github.com/pypa/virtualenv/pull/3250 github.com: https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6 github.com: https://github.com/pypa/virtualenv/releases/tag/21.7.12