HomePythonCVE-2024-9287

CVE-2024-9287

MEDIUM
5.3CVSS
Published: 2024-10-22
Updated: 2025-11-03
AI Analysis

Description

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS Metrics

Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green
Attack Vector
local
Complexity
low
Privileges
high
User Action
active
Confidentiality
undefined
Integrity
undefined
Availability
undefined
Weaknesses
CWE-428CWE-77

Metadata

Primary Vendor
PYTHON
Published
10/22/2024
Last Modified
11/3/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

python : pythonpython : pythonpython : pythonpython : pythonpython : pythonpython : python

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief