CVE-2026-22702

Public on 2026-01-10
Modified on 2026-01-12
Description
virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory creation operations. An attacker with local access can exploit a race condition between directory existence checks and creation to redirect virtualenv's app_data and lock file operations to attacker-controlled locations. This issue has been patched in version 20.36.1.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core python-virtualenv Not Affected
Amazon Linux 2023 python-virtualenv Pending Fix
Amazon Linux 2023 python3.13-virtualenv Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L