Loading HuntDB...

GHSA-grqq-hcc7-crmr

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

Related CVEs

Key Information

GHSA ID
GHSA-grqq-hcc7-crmr
Published
October 22, 2024 6:32 PM
Last Modified
April 26, 2025 12:30 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.