{"id":"GHSA-5qvp-pr9f-2g2v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-5qvp-pr9f-2g2v","summary":"poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645","details":"Pin vulnerable version of requests library","published":"2026-04-01T20:52:20Z","modified":"2026-04-01T21:04:43.804300Z","cvss":{"score":4.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"poetry-plugin-tweak-dependencies-version","fixedVersion":"1.5.6"}],"fix":{"url":"https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version/commit/54b5784d89f36cd413a8bc5032ab0a96438dcae3","label":"sbrunner/poetry-plugin-tweak-dependencies-version@54b5784"},"references":[{"type":"WEB","url":"https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"},{"type":"WEB","url":"https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version/security/advisories/GHSA-5qvp-pr9f-2g2v"},{"type":"WEB","url":"https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version/commit/54b5784d89f36cd413a8bc5032ab0a96438dcae3"},{"type":"PACKAGE","url":"https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version"},{"type":"WEB","url":"https://github.com/sbrunner/poetry-plugin-tweak-dependencies-version/releases/tag/1.5.6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-01T21:04:43.804300Z"}}