
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34591 is a path traversal vulnerability in Poetry, the Python dependency manager, that allows arbitrary file writes with the privileges of the Poetry process. Affecting versions 1.4.0 through 2.3.2, the flaw enables a crafted wheel package containing ../ path sequences to write files outside the intended installation directory during normal package install flows. It was reported by researcher bekkaze, patched by radoering on March 29, 2026, and publicly disclosed on March 31, 2026. The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, Poetry Security Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), where Poetry's WheelDestination.write_to_fs() method in src/poetry/installation/wheel_installer.py constructs the target file path by directly joining an untrusted wheel entry path to the scheme directory without first resolving or validating it. Specifically, the vulnerable code at line 47 performs target_path = Path(self.scheme_dict[scheme]) / path without any resolve() + is_relative_to() guard, allowing ../ sequences embedded in wheel archive entries to escape the target directory. This sink is reachable via the normal installation flow through src/poetry/installation/executor.py:607. The fix, introduced in PR #10792, resolves both the scheme directory and the computed target path, then checks target_path.is_relative_to(target_dir) before writing, aborting installation if the check fails (Poetry Security Advisory, Fix Commit).
Successful exploitation allows an attacker to write arbitrary files to any location accessible by the Poetry process, including overwriting system files, configuration files, or planting malicious scripts in startup directories or CI/CD pipeline paths. The primary impact is a high integrity violation — confidentiality and availability are not directly affected by the file write itself. However, if a user subsequently imports or invokes the installed malicious package, arbitrary code execution becomes possible, potentially enabling lateral movement within CI/CD environments or developer workstations (GitHub Advisory, Poetry Security Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, consisting of a self-contained Python script that creates a malicious wheel with a ../../pwned.txt traversal entry and invokes Poetry's WheelDestination and install() to demonstrate the arbitrary file write (Poetry Security Advisory). No in-the-wild exploitation has been observed as of the time of disclosure. The EPSS score is approximately 0.095% (0.019% per GitHub Advisory), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction — a victim must run poetry install or equivalent against a malicious or compromised package source (GitHub Advisory).
.whl, which is a ZIP file) containing a file entry with a path traversal sequence such as ../../pwned.txt alongside legitimate package files and required metadata (WHEEL, METADATA, RECORD).poetry add <malicious-package> or poetry install against a pyproject.toml referencing the malicious package. Poetry's executor calls WheelDestination.write_to_fs() for each entry in the wheel.../../pwned.txt entry is written relative to the scheme directory, landing outside the virtual environment — e.g., in the project root or a parent directory — with the privileges of the Poetry process..pth file in site-packages, a shell startup script, or a CI/CD configuration file), code execution can be achieved when the file is loaded or the environment is next used (Poetry Security Advisory, Fix Commit).poetry install run (e.g., .txt, .py, .sh, or .pth files in parent directories of the venv); new or modified files in ~/.bashrc, ~/.profile, CI/CD configuration directories, or system site-packages that were not explicitly installed.poetry install referencing paths outside the expected installation directory.poetry install operation, particularly if the installed package was not from a trusted registry (Poetry Security Advisory).Upgrade Poetry to version 2.3.3 or later, which resolves target paths using Path.resolve() and validates them with is_relative_to() before writing, aborting installation if a traversal is detected (Poetry Release 2.3.3, Fix PR). No configuration-based workaround is available for vulnerable versions. As a defense-in-depth measure, restrict Poetry installations to trusted package sources and verified registries, and avoid installing packages from untrusted or third-party indexes in sensitive environments such as CI/CD pipelines.
The SUSE Linux security team issued an advisory and update for python-poetry addressing this CVE, and it was covered by Linux security news outlets including LinuxSecurity.com and pro-linux.de (openSUSE Security Announce). A blog post on package manager CWEs referenced this vulnerability in the context of supply chain security risks for Python tooling. The OpenHands project issued a fix specifically to update Poetry to 2.3.3 in response to this CVE. Community reaction was generally measured, noting that while the arbitrary file write is serious, actual code execution requires a secondary user action (importing the malicious package).
Fix availability across major Linux distributions and their releases.
devel
poetry
jammy
poetry
jammy (esm-apps)
poetry
noble
poetry
noble (esm-apps)
poetry
resolute
poetry
resolute (esm-apps)
poetry
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."