Vendor
The virtualenv library lacks integrity checks for downloaded pip and setuptools seed wheels, enabling potential arbitrary code execution via compromised mirrors or MITM attacks.