virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Hunt.io Blog


Check out our latest threat hunting articles, tips and stories.

Highlights

  • Articles covering categories such as malware, campaigns, and others.
  • It's helpful for red teamers.
Listed: