---
id: CVE-2026-41140
title: >-
  poetry: Poetry: Path traversal vulnerability allows arbitrary file write via
  malicious package extraction (CVE-2026-41140)
summary: >-
  A flaw was found in Poetry, a dependency manager for Python. This
  vulnerability allows a remote attacker to perform a path traversal attack. By
  crafting a malicious software package, the `extractall()` function in Poetry
  can be tricked int…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H'
cvssSource: vendor
cwe: CWE-22
vendor: Red Hat
product: Red Hat Ansible Automation Platform 2.6
affected:
  - ansible_automation_platform 2
  - ansible_automation_platform 2.6
patched:
  - ansible_automation_platform 2.6
published: '2026-04-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:27:16+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41140.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41140.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-41140'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2461604'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-41140'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41140'
  - url: >-
      https://github.com/python-poetry/poetry/security/advisories/GHSA-73h3-mf4w-8647
  - url: 'https://access.redhat.com/errata/RHSA-2026:24866'
  - url: 'https://github.com/python-poetry/poetry'
  - url: 'https://github.com/python-poetry/poetry/releases/tag/2.3.4'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00472
epssPercentile: 0.38145
aliases:
  - GHSA-73h3-mf4w-8647
  - PYSEC-2026-2890
ecosystem: pip
ingestedAt: '2026-07-13T18:57:54.078Z'
---

## Overview

A flaw was found in Poetry, a dependency manager for Python. This vulnerability allows a remote attacker to perform a path traversal attack. By crafting a malicious software package, the `extractall()` function in Poetry can be tricked into writing files to unintended locations on the system. This could lead to the creation or overwrite of critical system files, potentially compromising the integrity of the system.

## Vendor advisories

- **RHSA-2026:24866** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24866)
- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2 · no fix planned: Red Hat Ansible Automation Platform 2 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41140.json)

**poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction** — rated Important by Red Hat. Released 2026-04-24, updated 2026-09-24.

Affected:

- Red Hat Ansible Automation Platform 2

Fixed:

- Red Hat Ansible Automation Platform 2.6

No fix planned:

- Red Hat Ansible Automation Platform 2

Not affected:

- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Satellite 6

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade https://access.redhat.com/errata/RHSA-2026:24866

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-41140)

Affected packages:

- `poetry < 2.3.4`

Patched in:

- `poetry 2.3.4`

Source: https://osv.dev/vulnerability/GHSA-73h3-mf4w-8647
