VDB
Sign up
MEDIUM4.4

GHSA-5qvp-pr9f-2g2v

poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645

Quick fix

GHSA-5qvp-pr9f-2g2v — poetry-plugin-tweak-dependencies-version: upgrade to the fixed version with the command below.

pip install --upgrade 'poetry-plugin-tweak-dependencies-version>=1.5.6'

Details

Pin vulnerable version of requests library

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/poetry-plugin-tweak-dependencies-version
Introduced in: 0Fixed in: 1.5.6
Fixpip install --upgrade 'poetry-plugin-tweak-dependencies-version>=1.5.6'

References