CVE-2026-102937 | pypa virtualenv up to 21.7.11 BatchActivator activate.bat BatchActivator.quote prompt/VIRTUALENV_PROMPT os command injection

SecurityVulns

A vulnerability was found in pypa virtualenv up to 21.7.11. It has been rated as critical. This issue affects the function BatchActivator.quote of the file activate.bat of the component BatchActivator. Performing a manipulation of the argument prompt/VIRTUALENV_PROMPT results in os command injection.

This vulnerability is cataloged as CVE-2026-102937. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More