CVE-2026-102938: virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Sep
Released
2026-10-03
Last Updated
2026-10-06
EPSS Score
0.14% (percentile: 2.8%)

Affected Products (1)

Other

  • 21846-17084

Revision History

  • 2026-10-03: Information published.
  • 2026-10-06: Information published.