virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
{
"nvd_published_at": "2024-11-24T16:15:06Z",
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-77",
"CWE-78"
],
"github_reviewed_at": "2025-01-13T17:01:51Z"
}