CVE-2026-102938: virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
pyvenv.cfg is a line-based format with no escape syntax. PyEnvCfg.write() wrote values verbatim, while PyEnvCfg._read_values() parses the file with str.splitlines(). A value containing a line boundary therefore became additional configuration lines, and because reading is last-wins, the injected keys replaced any key written earlier in the file.
References
- github.com/advisories/GHSA-9h9j-4vrj-gf7g
- github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4012.yaml
- github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140
- github.com/pypa/virtualenv/pull/3247
- github.com/pypa/virtualenv/releases/tag/21.7.11
- github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g
- nvd.nist.gov/vuln/detail/CVE-2026-102938
- pypi.org/project/virtualenv
Code Behaviors & Features
Detect and mitigate CVE-2026-102938 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →