Lucene search

K
osvGoogleOSV:CVE-2022-26184
HistoryMar 21, 2022 - 10:15 p.m.

CVE-2022-26184

2022-03-2122:15:08
Google
osv.dev
4
poetry
untrusted search path
vulnerability
windows os
software

AI Score

7.8

Confidence

High

EPSS

0.002

Percentile

61.7%

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

AI Score

7.8

Confidence

High

EPSS

0.002

Percentile

61.7%