VendorsPython-poetrypoetryany version
Vulnerabilities

Python-poetry Poetry any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-26184
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.
Published 2022-03-21 · Modified
9.8EPSS 0.019
CVE-2022-36069
Poetry Argument Injection vulnerability can lead to local Code Execution
Published 2022-09-07 · Modified
7.3EPSS 0.013
CVE-2022-36070
Poetry's Untrusted Search Path can lead to Local Code Execution on Windows
Published 2022-09-07 · Modified
7.3EPSS 0.004
CVE-2026-34591
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
Published 2026-04-02 · Analyzed
7.1EPSS 0.006