logo

Database

Server side template injection In virtualenv

Description

virtualenv allows command injection through activation scripts for a virtual environment virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-GWXXY – Vulnerability | Fluid Attacks Database