CVE-2024-53899

Publication date

2024-11-24 00:00:00

Family

mitre

State

PUBLISHED

Description

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.