python-poetry records
5 published records for vendor python-poetry.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-426 Untrusted Search Path2
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-26184No exploit | Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when uspython-poetry · poetry · CWE-426 | Critical9.8 | — | 1.9% | Mar 21, 2022 |
30Monitor | CVE-2022-42966No exploit | Exponential ReDoS in cleo leads to denial of servicepython-poetry · cleo · CWE-1333 | High7.5 | — | 1.0% | Nov 9, 2022 |
29Monitor | CVE-2022-36069No exploit | Poetry Argument Injection vulnerability can lead to local Code Executionpython-poetry · poetry · CWE-94 | High7.3 | — | 1.3% | Sep 7, 2022 |
29Monitor | CVE-2022-36070No exploit | Poetry's Untrusted Search Path can lead to Local Code Execution on Windowspython-poetry · poetry · CWE-426 | High7.3 | — | 0.4% | Sep 7, 2022 |
28Monitor | CVE-2026-34591No exploit | Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Writepython-poetry · poetry · CWE-22 | High7.1 | — | 0.6% | Apr 2, 2026 |
- CVE-2022-2618440Plan
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when us
CriticalCVSS 9.8No exploitEPSS 2%python-poetry · poetryMar 21, 2022
- CVE-2022-4296630Monitor
Exponential ReDoS in cleo leads to denial of service
HighCVSS 7.5No exploitEPSS 1%python-poetry · cleoNov 9, 2022
- CVE-2022-3606929Monitor
Poetry Argument Injection vulnerability can lead to local Code Execution
HighCVSS 7.3No exploitEPSS 1%python-poetry · poetrySep 7, 2022
- CVE-2022-3607029Monitor
Poetry's Untrusted Search Path can lead to Local Code Execution on Windows
HighCVSS 7.3No exploitEPSS 0%python-poetry · poetrySep 7, 2022
- CVE-2026-3459128Monitor
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
HighCVSS 7.1No exploitEPSS 1%python-poetry · poetryApr 2, 2026