CVE-2026-34591Patch(python-poetry / poetry)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch python-poetry poetry systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • poetry

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
poetry

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-09: 1Mentions · 2026-05-04: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 1Technical Details · 2026-05-04: 104-0905-04
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-091
Patch1
2026-05-041
General1
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-34591 (Poetry path traversal) – evergreen mitigation: • Check: poetry --version • Fix: pipx upgrade poetry (or zypper update python311-poetry) • Block: AppArmor profile denying /**/* rw outside project dir Read more: 👉 https://tinyurl.com/2evzfaad #Security #openSUSE https://t.co/Z5qZonVGLv

    Post summary

    The post provides concrete mitigation steps for CVE‑2026‑34591, detailing how to check, update Poetry, and enforce AppArmor restrictions, with a link for additional information.

    0001056
    1.5K followersView on X
  • SecureChap@SecureChap
    General

    Nineteen years separate the first cataloged package manager path traversal (CVE-2007-0469) from this year's rediscovery (CVE-2026-34591, CVE-2026-35206). Same bug class. Same archive-extraction primitive. Different ecosystem. A new survey by Nesbitt catalogs a dozen CWE patterns that hit npm, PyPI, RubyGems, Composer, Cargo, Go, Helm, NuGet, and Conda over and over. A few standouts: Argument injection into VCS tools - six separate CVEs in one tool alone across git, hg, and Perforce wrappers (CVE-2021-29472, CVE-2022-36069, CVE-2021-43809, CVE-2023-5752, CVE-2022-24440, plus one more). Integrity checks that fail open: CVE-2016-1252 (clearsigned parser accepted unsigned content), CVE-2022-31156 (sig check silently skipped on error), CVE-2022-46176 (missing SSH host key on git index clones). Dependency confusion was already CVE-2013-0334 - eight years before its 2021 fame. Terminal escape sequences in package metadata: at least nine CVEs across four ecosystems. CocoaPods CVE-2024-38368: an orphaned admin API was left in place for ten years, until a researcher used it to claim 1,800 packages. The thesis: knowledge doesn't transfer between projects. Every ecosystem rediscovers the same dozen bugs from scratch. http://nesbitt.io/2026/05/04/package-manager-cwes.html

    Post summary

    The article surveys recurring CVE patterns across multiple package managers, highlighting similar bug classes but does not provide PoC code, exploits, patches, or evidence of active exploitation.

    0000043
    44 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppython-poetrypoetry-python-

Explore more