© 2025-2026 PySpect
First version without a known vulnerability: 2.3.4
Poetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
Fixed in: 2.3.4
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
Fixed in: 2.3.3
Poetry vulnerable to Untrusted Search Path leading to Local Code Execution on Windows
Fixed in: 1.1.9
Poetry Argument Injection can lead to Local Code Execution
Fixed in: 1.1.9
Poetry before v1.1.9 contains Untrusted Search Path
Fixed in: 1.1.9