virtualenv is vulnerable to Path Traversal
65
Medium Risk
Affected versions of this package are vulnerable to path traversal due to improper validation of paths within zipapp archives. The affected logic determines whether a resolved path stays within the archive using string-based prefix checks after os.path.realpath, which is unreliable across platforms and can be bypassed in edge cases involving path separators or symlinks. An attacker able to supply crafted paths can cause resolution outside the intended archive boundary, potentially accessing unintended files on the filesystem.
You are affected if you are using a version that falls within the vulnerable range.
virtualenv is vulnerable to Path Traversal in versions 20.0.0 - 21.2.3.
Upgrade the virtualenv library to a patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant