virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53899.json"