ZeroHour

CVE-2022-26184

CVSS 3.1
9.8 critical
EPSS
2%p78
Published
()
Modified
Description

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Vendors
python-poetry
Products
poetry
Weakness
CWE-426
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.