CVE-2026-102938 MEDIUM

CVE-2026-102938: virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

Vendor Pypa
Product virtualenv
Weakness CWE-93 · CRLF injection
Published September 29, 2026
Last update September 30, 2026

CVSS base score

5.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the last value for duplicate keys. An attacker who influences --prompt, VIRTUALENV_PROMPT, or configuration input can insert a recognized line boundary and additional keys, including home, causing consumers to use an attacker-selected base interpreter or corrupted environment metadata. The security impact requires prompt input from outside the operator's trust boundary; directly supplied prompt content primarily corrupts the operator's own environment. This issue is fixed in version 21.7.11.

Key dates

02Disclosure timeline

September 29, 2026 CVE published
September 30, 2026 Record updated

Related vulnerabilities

04Related CVE