AZL-105648

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105648.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105648
Upstream
Published
2026-09-29T21:17:18Z
Modified
2026-10-03T14:16:37Z
Summary
CVE-2026-102937 affecting package python-pip 24.2-10
Details

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax. When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12.

References

Affected packages

Azure Linux:3 / python-pip

Package

Name
python-pip
Purl
pkg:rpm/azure-linux/python-pip

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
24.2-10

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105648.json"