
🪟 Poetry tar extraction path traversal (CVE-2026-41140) = your CI can be “helpfully” redirected by a crafted archive. Supply-chain bugs don’t need kernels, just automation. #Windows #Microsoft #Security #CVE #DevOps #Python #Poetry https://windowsforum.com/threads/cve-2026-41140-poetry-path-traversal-in-source-tar-extracts-explained-for-windows.422522/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #SupplyChainRisk https://t.co/kbjiCu7ROi
Post summary
The tweet announces a path‑traversal vulnerability in Poetry’s tar extraction used in CI environments, but does not provide a PoC, exploit code, or patch information.

