CVE-2026-102930: CVE-2026-102930: Remote Code Execution via Unverified Dynamic Wheel Downloads in virtualenv
CVE-2026-102930: Remote Code Execution via Unverified Dynamic Wheel Downloads in virtualenv Vulnerability ID: CVE-2026-102930 CVSS Score: 7.7 Published: 2026-09-30 CVE-2026-102930 is a high-severity supply chain vul
CVE-2026-102930: Remote Code Execution via Unverified Dynamic Wheel Downloads in virtualenv
Vulnerability ID: CVE-2026-102930
CVSS Score: 7.7
Published: 2026-09-30
CVE-2026-102930 is a high-severity supply chain vulnerability in virtualenv prior to version 21.7.12. The download_wheel() function lacks integrity checks when dynamically fetching seed packages (such as pip or setuptools) over the network. This allows an attacker to intercept the network stream, replace packages with backdoored components, and achieve arbitrary code execution inside newly spawned virtual environments.
TL;DR
Prior to 21.7.12, virtualenv dynamically downloaded core python wheels without verifying their hashes, allowing network interceptors to inject backdoored code into newly created virtual environments.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-494
- Attack Vector: Network
- CVSS v4.0 Score: 7.7
- EPSS Score: None
- Impact: Arbitrary Code Execution
- Exploit Status: PoC-level
- KEV Status: Not Listed
Affected Systems
- virtualenv
-
virtualenv: < 21.7.12 (Fixed in:
21.7.12)
Code Analysis
Commit: a01ed3e
Implement hash verification of seed packages via PyPI's JSON API.
Mitigation Strategies
- Upgrade virtualenv to version 21.7.12 or newer to enforce integrity checks.
- Avoid using the --download flag unless strictly necessary.
- Enforce the index configuration using system environment variables like PIP_INDEX_URL to force validation bypasses on trusted internal mirrors.
Remediation Steps:
- Run 'pip install --upgrade virtualenv' to patch local systems.
- Configure internal package mirrors via environment variables in automated pipelines to ensure consistent trust structures.
- Monitor build server caches (e.g., ~/.local/share/virtualenv/wheel/) for modified and unverified wheel archives.
References
Read the full report for CVE-2026-102930 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.