« Volver al listado

Python-poetry

Python-poetry Poetry: vulnerabilidades y CVE

Python-poetry Poetry tiene 5 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses2
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-41140Baja (0.6)0.47%—24 abr 2026
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where…
CVE-2026-34591Alta (7.1)0.55%—2 abr 2026
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the…
CVE-2022-36070Alta (7.3)0.36%—7 sept 2022
Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and…
CVE-2022-36069Alta (7.3)1.3%—7 sept 2022
Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. These commands are constructed using user…
CVE-2022-26184Crítica (9.8)1.9%—21 mar 2022
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution1
  2. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Python-poetry