WhisperX tag archive

#symlink-attack

This page collects WhisperX intelligence signals tagged #symlink-attack. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-02 21:54:07 · GitHub Issues

1. CVE-2026-22702: TOCTOU Race Condition in virtualenv Enables Symlink-Based Directory Attacks

A Time-of-Check-Time-of-Use (TOCTOU) vulnerability has been identified in the virtualenv package (versions up to and including 20.36.1), potentially allowing local attackers to perform symlink-based directory manipulation attacks. The flaw exists in how virtualenv handles directory creation operations, creating a race ...