CVE-2026-34591 is a path traversal vulnerability (CWE-22) affecting Poetry, a Python dependency manager, in versions 1.4.0 through 2.3.2. A crafted wheel containing "../" paths can lead to arbitrary file write on the system with the Poetry process's privileges during package installation. Rated High (CVSS 7.1), this vulnerability requires user interaction to install a malicious package, but allows an unauthenticated attacker to achieve significant integrity impact. There is currently no evidence of active exploitation, nor are public exploit codes available. Community discussion and media coverage are minimal, and its EPSS score is very low, indicating a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.0, < 2.3.3CPE matchmatch criteria | cpe:2.3:a:python-poetry:poetry:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.