CVE-2026-102938 | pypa virtualenv up to 21.7.10 Configuration Parsing pyvenv.cfg PyEnvCfg._read_values –prompt/VIRTUALENV_PROMPT/configuration input input validation
A vulnerability categorized as problematic has been discovered in pypa virtualenv up to 21.7.10. Impacted is the function PyEnvCfg._read_values of the file pyvenv.cfg of the component Configuration Parsing. Executing a manipulation of the argument –prompt/VIRTUALENV_PROMPT/configuration input can lead to improper input validation.
This vulnerability is registered as CVE-2026-102938. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More