openSUSE 15.6 python-poetry Vulnerability Allows Arbitrary File Write

openSUSE 15.6 python-poetry Vulnerability Allows Arbitrary File Write

First seen 9 Apr 2026, 13:30 UTC Linuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

A vulnerability identified as CVE-2026-34591 affects python-poetry versions from 1.4.0 to before 2.3.3. The flaw allows crafted wheels to contain '../' paths that the Poetry tool writes to disk without proper containment checks, leading to arbitrary file writes. This issue impacts users of openSUSE Leap 15.6, where the affected package is python311-poetry version 1.7.1. The vulnerability was published on April 2, 2026, and has been assigned a CVSS score of 7.1, indicating a moderate severity risk. Users are advised to apply the patch provided in the advisory to mitigate the risk. The patch can be installed using SUSE's recommended methods, including YaST online_update or the zypper command. This update is crucial for maintaining system integrity and preventing unauthorized file modifications.

Key Points: • CVE-2026-34591 allows arbitrary file writes due to improper path handling in python-poetry. • The vulnerability affects openSUSE Leap 15.6 with python311-poetry versions 1.4.0 to before 2.3.3. • Users should apply the patch immediately to mitigate potential risks.

Timeline

2026-04-02
CVE-2026-34591 published
2026-04-09
openSUSE releases patch for python-poetry vulnerability