CVE-2024-53899: Virtualenv

High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Affected products

  • Virtualenv Virtualenv: before 20.26.6 (fixed in 20.26.6)

Published 2024-11-24. Last modified 2026-06-17.