You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-41140
About this tag
CVE-2026-41140 is a path-traversal vulnerability in the Poetry package manager, affecting source-distribution tar extraction on Python versions 3.10.0 through 3.10.12 and 3.11.0 through 3.11.4. The flaw allows crafted archives to escape intended directories, potentially leading to privileged file writes in development and CI environments. While not a Windows kernel or browser zero-day, it represents a supply-chain risk for Windows developers and administrators who rely on Poetry for dependency management. The vulnerability is fixed in Poetry version 2.3.4 and later. Discussions on WindowsForum.com focus on understanding the impact on Windows-based development workflows and mitigation strategies.
Microsoft has listed CVE-2026-41140 as a Poetry path-traversal flaw affecting source-distribution tar extraction when Poetry versions before 2.3.4 run on Python 3.10.0 through 3.10.12 or Python 3.11.0 through 3.11.4, exposing development and CI environments to crafted archives that escape their...