MEDIUM4.4
GHSA-5qvp-pr9f-2g2v
poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
Quick fix
GHSA-5qvp-pr9f-2g2v — poetry-plugin-tweak-dependencies-version: upgrade to the fixed version with the command below.
pip install --upgrade 'poetry-plugin-tweak-dependencies-version>=1.5.6'Details
Pin vulnerable version of requests library
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/poetry-plugin-tweak-dependencies-version
Introduced in:
0Fixed in: 1.5.6Fix
pip install --upgrade 'poetry-plugin-tweak-dependencies-version>=1.5.6'References
- https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2[WEB]
- https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version/security/advisories/GHSA-5qvp-pr9f-2g2v[WEB]
- https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version/commit/54b5784d89f36cd413a8bc5032ab0a96438dcae3[WEB]
- https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version[PACKAGE]
- https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version/releases/tag/1.5.6[WEB]