CVE-2024-9287
published 2024-10-22CVE-2024-9287: A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.65%
46.9th percentile
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) |
| debian | python-virtualenv | < python-virtualenv 20.26.6+ds-1 (forky) | python-virtualenv 20.26.6+ds-1 (forky) |
| debian | python2.7 | < pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) |
| debian | python3.11 | < pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) |
| debian | python3.13 | < pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) |
| debian | python3.9 | < pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u3 (bookworm) |
| msrc | azl3_python-virtualenv_20.25.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python-virtualenv_20.14.0-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-11_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| python | python | < 3.9.21 | 3.9.21 |
| python | python | — | — |
| python | python | >= 3.10.0 < 3.10.16 | 3.10.16 |
| python | python | >= 3.11.0 < 3.11.11 | 3.11.11 |
| python | python | >= 3.12.0 < 3.12.8 | 3.12.8 |
| python | python | >= 3.13.0 < 3.13.1 | 3.13.1 |
| python_software_foundation | cpython | < 3.9.21 | 3.9.21 |
| python_software_foundation | cpython | >= 3.10.0 < 3.10.16 | 3.10.16 |
| python_software_foundation | cpython | >= 3.11.0 < 3.11.11 | 3.11.11 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green
ghsa5.3MEDIUM
osv7.8HIGH
vendor_msrc8.4HIGH
vendor_debian7.8HIGH
vendor_oracle7.8MEDIUM
vendor_redhat7.8HIGH
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Python) — CVE-2024-9287
vendor_oracle·2025-07-15·CVSS 7.8
CVE-2024-9287 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Python) — CVE-2024-9287
Oracle Oracle Communications Applications Risk Matrix: Core (Python) vulnerability
CVE: CVE-2024-9287
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Ubuntu
Python vulnerabilities
vendor_ubuntu·2025-05-06·CVSS 3.7
CVE-2024-11168 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled parsing bracketed hosts.
A remote attacker could possibly use this issue to perform a Server-Side
Request Forgery (SSRF) attack. This issue only affected python 2.7 and
python3.4 on Ubuntu 14.04 LTS; python2.7 on Ubuntu 16.04 LTS;
python2.7, python3.6, python3.7, and python3.8 on Ubuntu 18.04 LTS;
python2.7 and python3.9 on Ubuntu 20.04 LTS; and python2.7 and
python3.11 on Ubuntu 22.04 LTS. (CVE-2024-11168)
It was discovered that Python allowed excessive backtracking while
parsing certain tarfile headers. A remote attacker could possibly use
this issue to cause Python to consume excessive resources, leading to
a denial of service. This issue only affecte
Ubuntu
Python regression
vendor_ubuntu·2025-03-24·CVSS 3.7
CVE-2025-0938 [LOW] Python regression
Title: Python regression
Summary: USN-7348-1 introduced a regression in Python.
USN-7348-1 fixed vulnerabilities in Python. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python ipaddress module contained incorrect
information about which IP address ranges were considered “private” or
“globally reachable”. This could possibly result in applications applying
incorrect security policies. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2024-4032)
It was discovered that Python incorrectly handled quoting path names when
using the venv module. A local attacker able to control virtual
environments could possibly use this issue to execute arbitrary code when
the
Ubuntu
Python vulnerabilities
vendor_ubuntu·2025-03-12·CVSS 3.7
CVE-2024-9287 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that the Python ipaddress module contained incorrect
information about which IP address ranges were considered “private” or
“globally reachable”. This could possibly result in applications applying
incorrect security policies. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2024-4032)
It was discovered that Python incorrectly handled quoting path names when
using the venv module. A local attacker able to control virtual
environments could possibly use this issue to execute arbitrary code when
the virtual environment is activated. (CVE-2024-9287)
It was discovered that Python incorrectly handled parsing bracketed hosts.
A remote attacker could possibly use this iss
Red Hat
virtualenv: potential command injection via virtual environment activation scripts
vendor_redhat·2024-11-24·CVSS 7.8
CVE-2024-53899 [HIGH] CWE-78 virtualenv: potential command injection via virtual environment activation scripts
virtualenv: potential command injection via virtual environment activation scripts
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
A flaw was found in the virtualenv Python package. Due to the improper handling of quotes in magic template strings, the virtual environment activation script is vulnerable to OS command injection,leading to the loss of confidentiality,integrity and availability of the system.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread insta
Ubuntu
Python vulnerability
vendor_ubuntu·2024-11-19
CVE-2024-9287 Python vulnerability
Title: Python vulnerability
Summary: Python could be made to run programs when activating virtual environments.
It was discovered that Python incorrectly handled quoting path names when
using the venv module. A local attacker able to control virtual
environments could possibly use this issue to execute arbitrary code when
the virtual environment is activated.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same
vendor_msrc·2024-11-12·CVSS 8.4
CVE-2024-53899 [HIGH] CWE-77 virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, w
Red Hat
python: Virtual environment (venv) activation scripts don't quote paths
vendor_redhat·2024-10-22·CVSS 5.3
CVE-2024-9287 [MEDIUM] CWE-428 python: Virtual environment (venv) activation scripts don't quote paths
python: Virtual environment (venv) activation scripts don't quote paths
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.
A vulnerability has been found in the Python `venv` module and CLI. Path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject
Microsoft
Virtual environment (venv) activation scripts don't quote paths
vendor_msrc·2024-10-08·CVSS 7.8
CVE-2024-9287 [MEDIUM] CWE-428 Virtual environment (venv) activation scripts don't quote paths
Virtual environment (venv) activation scripts don't quote paths
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://l
Debian
CVE-2024-9287: pypy3 - A vulnerability has been found in the CPython `venv` module and CLI where path n...
vendor_debian·2024·CVSS 5.3
CVE-2024-9287 [MEDIUM] CVE-2024-9287: pypy3 - A vulnerability has been found in the CPython `venv` module and CLI where path n...
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.
Scope: local
bookworm: resolved (fixed in 7.3.11+dfsg-2+deb12u3)
bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u4)
forky: resolved (fixed in 7.3.17+dfsg-3)
sid: resolved (fixed in 7.3.17+dfsg-3)
trixie: resolved (fixed in 7.3.17+dfsg-3)
Debian
CVE-2024-53899: python-virtualenv - virtualenv before 20.26.6 allows command injection through the activation script...
vendor_debian·2024·CVSS 7.8
CVE-2024-53899 [HIGH] CVE-2024-53899: python-virtualenv - virtualenv before 20.26.6 allows command injection through the activation script...
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 20.26.6+ds-1)
sid: resolved (fixed in 20.26.6+ds-1)
trixie: resolved (fixed in 20.26.6+ds-1)
OSV
python vulnerabilities
osv·2025-05-06·CVSS 6.3
CVE-2024-11168 [MEDIUM] python vulnerabilities
python vulnerabilities
It was discovered that Python incorrectly handled parsing bracketed hosts.
A remote attacker could possibly use this issue to perform a Server-Side
Request Forgery (SSRF) attack. This issue only affected python 2.7 and
python3.4 on Ubuntu 14.04 LTS; python2.7 on Ubuntu 16.04 LTS;
python2.7, python3.6, python3.7, and python3.8 on Ubuntu 18.04 LTS;
python2.7 and python3.9 on Ubuntu 20.04 LTS; and python2.7 and
python3.11 on Ubuntu 22.04 LTS. (CVE-2024-11168)
It was discovered that Python allowed excessive backtracking while
parsing certain tarfile headers. A remote attacker could possibly use
this issue to cause Python to consume excessive resources, leading to
a denial of service. This issue only affected python3.4 on
Ubuntu 14.04 LTS; python3.6, python3.7, and pyth
OSV
python3.5, python3.8 regression
osv·2025-03-24·CVSS 6.3
[MEDIUM] python3.5, python3.8 regression
python3.5, python3.8 regression
USN-7348-1 fixed vulnerabilities in Python. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python ipaddress module contained incorrect
information about which IP address ranges were considered “private” or
“globally reachable”. This could possibly result in applications applying
incorrect security policies. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2024-4032)
It was discovered that Python incorrectly handled quoting path names when
using the venv module. A local attacker able to control virtual
environments could possibly use this issue to execute arbitrary code when
the virtual environment is activated. (CVE-2024-9287
OSV
python3.5, python3.8 vulnerabilities
osv·2025-03-12·CVSS 6.3
CVE-2024-4032 [MEDIUM] python3.5, python3.8 vulnerabilities
python3.5, python3.8 vulnerabilities
It was discovered that the Python ipaddress module contained incorrect
information about which IP address ranges were considered “private” or
“globally reachable”. This could possibly result in applications applying
incorrect security policies. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2024-4032)
It was discovered that Python incorrectly handled quoting path names when
using the venv module. A local attacker able to control virtual
environments could possibly use this issue to execute arbitrary code when
the virtual environment is activated. (CVE-2024-9287)
It was discovered that Python incorrectly handled parsing bracketed hosts.
A remote attacker could possibly use this issue to perform a Server-Side
Request Forgery (SSRF
OSV
virtualenv allows command injection through activation scripts for a virtual environment
osv·2024-11-24·CVSS 5.3
CVE-2024-53899 [MEDIUM] virtualenv allows command injection through activation scripts for a virtual environment
virtualenv allows command injection through activation scripts for a virtual environment
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
GHSA
virtualenv allows command injection through activation scripts for a virtual environment
ghsa·2024-11-24·CVSS 5.3
CVE-2024-53899 [MEDIUM] CWE-77 virtualenv allows command injection through activation scripts for a virtual environment
virtualenv allows command injection through activation scripts for a virtual environment
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
OSV
CVE-2024-53899: virtualenv before 20
osv·2024-11-24·CVSS 7.8
CVE-2024-53899 [HIGH] CVE-2024-53899: virtualenv before 20
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
OSV
CVE-2024-9287: A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted prop
osv·2024-10-22·CVSS 5.3
CVE-2024-9287 [MEDIUM] CVE-2024-9287: A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted prop
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.
GHSA
GHSA-grqq-hcc7-crmr: A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted prop
ghsa_unreviewed·2024-10-22
CVE-2024-9287 [MEDIUM] CWE-428 GHSA-grqq-hcc7-crmr: A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted prop
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, July 2025 Security Update Review
blogs_qualys·2025-07-16
Oracle Critical Patch Update, July 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the July Critical Patch Update (about 74%) are for non-Oracle CVEs, su
Qualys
Oracle Critical Patch Update, July 2025 Security Update Review | Qualys
blogs_qualys·2025-07-16
Oracle Critical Patch Update, July 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the July Critical Patch Update (about 74%) are for non-Oracle CVE
Bugzilla
CVE-2024-53899 virtualenv: potential command injection via virtual environment activation scripts
bugzilla·2024-11-24·CVSS 7.8
CVE-2024-53899 [HIGH] CVE-2024-53899 virtualenv: potential command injection via virtual environment activation scripts
CVE-2024-53899 virtualenv: potential command injection via virtual environment activation scripts
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:10953 https://access.redhat.com/errata/RHSA-2024:10953
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via RHSA-2024:11048 https://access.redhat.com/errata/RHSA-2024:11048
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.2 Advanced Update Support
Via RHSA
https://github.com/python/cpython/commit/633555735a023d3e4d92ba31da35b1205f9ecbd7https://github.com/python/cpython/commit/8450b2482586857d689b6658f08de9c8179af7dbhttps://github.com/python/cpython/commit/9286ab3a107ea41bd3f3c3682ce2512692bdded8https://github.com/python/cpython/commit/ae961ae94bf19c8f8c7fbea3d1c25cc55ce8ae97https://github.com/python/cpython/commit/d48cc82ed25e26b02eb97c6263d95dcaa1e9111bhttps://github.com/python/cpython/commit/e52095a0c1005a87eed2276af7a1f2f66e2b6483https://github.com/python/cpython/issues/124651https://github.com/python/cpython/pull/124712https://mail.python.org/archives/list/[email protected]/thread/RSPJ2B5JL22FG3TKUJ7D7DQ4N5JRRBZL/https://lists.debian.org/debian-lts-announce/2024/11/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2024/12/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20250425-0006/
2024-10-22
Published