CVE-2026-41140

Source
https://cve.org/CVERecord?id=CVE-2026-41140
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41140.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41140
Aliases
Downstream
Published
2026-04-24T17:10:33.869Z
Modified
2026-07-16T03:30:52.283518052Z
Severity
  • 0.6 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
Details

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailable. Considering only Python versions which are still supported by Poetry, these are 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4. This vulnerability is fixed in 2.3.4.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41140.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/python-poetry/poetry

Affected ranges

Type
GIT
Repo
https://github.com/python-poetry/poetry
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.3.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.12.0
0.12.0a0
0.12.0a1
0.12.0a2
0.12.0a3
0.12.0a4
0.12.0a5
0.12.1
0.12.2
0.12.3
0.12.4
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
0.9.1
1.*
1.0.0
1.0.0a0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.2.0b1
1.2.0b2
1.2.0b3
1.2.0rc1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.8.0
2.*
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41140.json"