AZL-105666

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105666.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105666
Upstream
Published
2026-09-29T21:17:18Z
Modified
2026-10-03T14:16:38Z
Summary
CVE-2026-102937 affecting package python-virtualenv 20.36.1-6
Details

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax. When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12.

References

Affected packages

Azure Linux:3 / python-virtualenv

Package

Name
python-virtualenv
Purl
pkg:rpm/azure-linux/python-virtualenv

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
20.36.1-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105666.json"