Signal is active with 1 mentions in latest observed window
Immediate actions
Patch python-poetry poetry systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifacts during normal install flows. (Normally, installing a malicious wheel is not sufficient for execution of malicious code. Malicious code will only be executed after installation if the malicious package is imported or invoked by the user.). This issue has been patched in version 2.3.3.
The post provides concrete mitigation steps for CVE‑2026‑34591, detailing how to check, update Poetry, and enforce AppArmor restrictions, with a link for additional information.
Nineteen years separate the first cataloged package manager path traversal (CVE-2007-0469) from this year's rediscovery (CVE-2026-34591, CVE-2026-35206). Same bug class. Same archive-extraction primitive. Different ecosystem.
A new survey by Nesbitt catalogs a dozen CWE patterns that hit npm, PyPI, RubyGems, Composer, Cargo, Go, Helm, NuGet, and Conda over and over.
A few standouts:
Argument injection into VCS tools - six separate CVEs in one tool alone across git, hg, and Perforce wrappers (CVE-2021-29472, CVE-2022-36069, CVE-2021-43809, CVE-2023-5752, CVE-2022-24440, plus one more).
Integrity checks that fail open: CVE-2016-1252 (clearsigned parser accepted unsigned content), CVE-2022-31156 (sig check silently skipped on error), CVE-2022-46176 (missing SSH host key on git index clones).
Dependency confusion was already CVE-2013-0334 - eight years before its 2021 fame.
Terminal escape sequences in package metadata: at least nine CVEs across four ecosystems.
CocoaPods CVE-2024-38368: an orphaned admin API was left in place for ten years, until a researcher used it to claim 1,800 packages.
The thesis: knowledge doesn't transfer between projects. Every ecosystem rediscovers the same dozen bugs from scratch.
http://nesbitt.io/2026/05/04/package-manager-cwes.html
Post summary
The article surveys recurring CVE patterns across multiple package managers, highlighting similar bug classes but does not provide PoC code, exploits, patches, or evidence of active exploitation.