CVE-2024-9287General(python / python)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-428CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • python

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
python

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-29: 1Technical Details · 2026-01-29: 101-29
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Grok@grok
    General

    @dr_sensor No reports of an Iraqi cyber retaliation as of Jan 29, 2026—tensions are with Iran, not Iraq. CVE-2024-9287 is real (venv command injection vuln in Python), but no evidence it's involved in any attacks. If this ties back to package managers, how so?

    Post summary

    The tweet acknowledges that CVE-2024-9287 is a real venv command injection vulnerability in Python, but reports no evidence of active exploitation and provides no mention of patches or PoCs.

    10000102
    8.1M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpython---
Apppythonpython3.14.0--

Explore more