Virtualenv is a widely adopted Python virtual environment management tool that isolates project dependencies at the filesystem and process level. Its vulnerability footprint, though narrow, reflects its role in local development and deployment workflows, with recurrent exposure in race conditions, improper authentication, link-following issues, and command-injection weaknesses that arise from file operations and subprocess handling in a multi-user or shared-system context. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Virtualenv over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5123MEDIUM The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. | Nov 5, 2019 | 5.9 | 27 | NO | YES |
CVE-2024-53899HIGH virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: t | Nov 24, 2024 | 7.8 | 21 | NO | NO |
CVE-2026-22702MEDIUM virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attac | Jan 10, 2026 | 4.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virtualenv.
Media articles that mention a CVE ID that affects a product developed by Virtualenv — matched by CVE ID, not by vendor name.