virtualenv is vulnerable to Path Traversal
65
Medium Risk
Affected versions of this package are vulnerable to path traversal due to improper validation of paths within zipapp archives. The affected logic determines whether a resolved path stays within the archive using string-based prefix checks after os.path.realpath, which is unreliable across platforms and can be bypassed in edge cases involving path separators or symlinks. An attacker able to supply crafted paths can cause resolution outside the intended archive boundary, potentially accessing unintended files on the filesystem.
You are affected if you are using a version that falls within the vulnerable range.
virtualenv is vulnerable to Path Traversal in versions 20.0.0 - 21.2.3.
Upgrade the virtualenv library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant