Skip to main content
Loading…
    CVE-2026-41140 — Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions — CVE Database · The Intelligence Room