Количество 8
Количество 8
BDU:2026-07551
Уязвимость менеджера зависимостей Poetry языка программирования Python, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260526-73-0022
Уязвимость poetry
CVE-2026-34591
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3.
CVE-2026-34591
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3.
CVE-2026-34591
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3.
CVE-2026-34591
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
CVE-2026-34591
Poetry is a dependency manager for Python. From version 1.4.0 to befor ...
GHSA-2599-h6xx-hpxp
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-07551 Уязвимость менеджера зависимостей Poetry языка программирования Python, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
ROS-20260526-73-0022 Уязвимость poetry | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-34591 Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34591 Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34591 Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34591 Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write | 0% Низкий | 3 месяца назад | ||
CVE-2026-34591 Poetry is a dependency manager for Python. From version 1.4.0 to befor ... | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-2599-h6xx-hpxp Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write | CVSS3: 6.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу