Skip to content

Affected by CVE-2026-25645

Moderate
sbrunner published GHSA-5qvp-pr9f-2g2v Mar 30, 2026

Package

pip poetry-plugin-tweak-dependencies-version (pip)

Affected versions

<=1.5.5

Patched versions

1.5.6

Description

Pin vulnerable version of requests

Severity

Moderate

CVE ID

CVE-2026-25645

Weaknesses

Insecure Temporary File

Creating and using insecure temporary files can leave application and system data vulnerable to attack. Learn more on MITRE.