Vulnerability record · CVE-2026-34591 · published 2 April 2026
CVE-2026-34591: Python-poetry poetry path traversal vulnerability
Python Poetry · Poetry
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3.
Description
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://github.com/python-poetry/poetry/commit/ed59537ac3709cfbdbf95d957de801c13872991a | Patch |
| https://github.com/python-poetry/poetry/pull/10792 | Issue TrackingPatch |
| https://github.com/python-poetry/poetry/releases/tag/2.3.3 | ProductRelease Notes |
| https://github.com/python-poetry/poetry/security/advisories/GHSA-2599-h6xx-hpxp | ExploitVendor Advisory |
| https://github.com/python-poetry/poetry/security/advisories/GHSA-2599-h6xx-hpxp | ExploitVendor Advisory |
Track CVE-2026-34591 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-34591), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.