CVE-2020-11073

HIGH

Autoswitch Python Virtualenv <0.16.0 - RCE

Title source: llm
STIX 2.1

Description

In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0

Scores

CVSS v3 7.9
EPSS 0.0054
EPSS Percentile 41.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Details

CWE
CWE-22 CWE-77
Status published
Products (1)
autoswitch_python_virtualenv_project/autoswitch_python_virtualenv < 1.16.0
Published May 13, 2020
Tracked Since Feb 18, 2026