PT-2026-34538 · Pypi+1 · Poetry+1

CVE-2026-41140

·

Published

2026-04-22

·

Updated

2026-07-13

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Poetry versions prior to 2.3.4
Description The extractall() function in src/poetry/utils/helpers.py extracts sdist tarballs without path traversal protection on Python versions where tarfile.data filter is unavailable. This occurs specifically on Python versions 3.10.0 through 3.10.12 and 3.11.0 through 3.11.4. An attacker can use a crafted sdist with ../../ tar member paths to perform arbitrary file writes outside the intended extraction directory. This can be achieved through direct path traversal, symlink traversal, or hardlink attacks. The issue is triggered during metadata resolution or when building a package from sdist.
Recommendations Update Poetry to version 2.3.4 or newer.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07726
CVE-2026-41140
GHSA-73H3-MF4W-8647
PYSEC-2026-2890

Affected Products

Poetry
Red Os