WhisperX tag archive

#CVE-2026-22702

This page collects WhisperX intelligence signals tagged #CVE-2026-22702. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-03 06:27:00 · GitHub Issues

1. Virtualenv Security Flaw: CVE-2026-22702 Exposes Python Environments to Local Symlink Attacks

A critical TOCTOU (Time-of-Check-Time-of-Use) vulnerability, tracked as CVE-2026-22702, has been disclosed in the widely used Python `virtualenv` tool. The flaw allows a local attacker to exploit a race condition during directory creation, enabling symlink-based attacks that could compromise the integrity and security ...

The Lab · 2026-05-02 21:54:07 · GitHub Issues

2. CVE-2026-22702: TOCTOU Race Condition in virtualenv Enables Symlink-Based Directory Attacks

A Time-of-Check-Time-of-Use (TOCTOU) vulnerability has been identified in the virtualenv package (versions up to and including 20.36.1), potentially allowing local attackers to perform symlink-based directory manipulation attacks. The flaw exists in how virtualenv handles directory creation operations, creating a race ...