CVE-2026-41140
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist t
CVSS
8.7
High
EPSS
0.3%
p22
KEV
—
Exploit Today
6
0-100
Published: Apr 24, 2026 · Last modified: Jul 15, 2026 · CWE-22
0.3%EPSS · 30 days0.3%
2026-08-102026-09-07
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailable. Considering only Python versions which are still supported by Poetry, these are 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4. This vulnerability is fixed in 2.3.4.
- github.comhttps://github.com/python-poetry/poetry/security/advisories/GHSA-73h3-mf4w-8647
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24866
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-41140
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2461604
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41140.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-748596.8 MED—
——0The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries.6hCVE-2026-865429.1 CRI—
——0knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.16hCVE-2026-865418.3 HIG—
——0knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or SSH configuration files.16hCVE-2026-865387.5 HIG—
——0knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.16hCVE-2026-864398.8 HIG—
——0knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.16hCVE-2026-63777.5 HIG—
——0Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal.
This issue affects CSM (Customer Service Management): from 6.8.9 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.1d