poetry
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting poetrypage 1 of 1
- CVE-2022-26184CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.1.92022-03-21
vulnerable: 0.1.0 ... 1.1.8 (136 versions)
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs …
- CVE-2022-36069HIGHCVSS 7.3EG 7.3✓ Fixed in 1.1.92022-09-07
vulnerable: 0.1.0 ... 1.1.8 (136 versions)
Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. These commands are constructed using user input (e.g. the repos…
- CVE-2022-36070HIGHCVSS 7.3EG 7.3✓ Fixed in 1.1.92022-09-07
vulnerable: 0.1.0 ... 1.1.8 (136 versions)
Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and not its absolute pa…
- CVE-2026-34591MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.3.32026-04-02
vulnerable: 1.4.0 ... 2.3.2 (27 versions)
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Po…
- CVE-2026-41140LOWCVSS 0.6EG 0.6✓ Fixed in 2.3.42026-04-24
vulnerable: 0.1.0 ... 2.3.3 (184 versions)
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailab…
Check whether poetry is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for poetry CVEs against the assets you own.
Start Free Scan →