CVE-2022-26184

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
21/03/2022
Last modified:
23/10/2023

Description

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python-poetry:poetry:*:*:*:*:*:*:*:* 1.1.9 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*