© 2025-2026 PySpect
First version without a known vulnerability: 21.7.13
virtualenv bash and fish activation scripts execute commands embedded in paths
Fixed in: 21.7.13
virtualenv: Command injection via --prompt in activate.bat (batch activator)
Fixed in: 21.7.12
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
Fixed in: 21.7.12
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
Fixed in: 21.7.11
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
Fixed in: 20.36.1
virtualenv allows command injection through activation scripts for a virtual environment
Fixed in: 20.26.6
Virtualenv Allows Symlink Attack on /tmp/
Fixed in: 1.5