virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory creation operations. An attacker with local access can exploit a race condition between directory existence checks and creation to redirect virtualenv's app_data and lock file operations to attacker-controlled locations. This issue has been patched in version 20.36.1.
CVSS Details
- CVSS 3.1 Base Score: 4.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-virtualenv | Jul 23, 2026 | Jul 23, 2026 |
| Freebsd | — | Upgrade py314-virtualenvUpgrade py310-virtualenvUpgrade py312-virtualenvUpgrade py313t-virtualenvUpgrade py311-virtualenvUpgrade py313-virtualenv | Jan 27, 2026 | Jan 12, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python3-virtualenv | Mar 10, 2026 | Mar 10, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 10, 2026 |
| Suse | — | Upgrade python313-virtualenvUpgrade python311-virtualenv | Jan 23, 2026 | Jan 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub