SCA: security update for poetry-plugin-tweak-dependencies-version (GHSA-5qvp-pr9f-2g2v)

high Tenable Self-Hosted Container Security Plugin ID 439674

Description

poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645

Solution

Update the poetry-plugin-tweak-dependencies-version library and its related packages to version 1.5.6 or later.

See Also

https://github.com/advisories/GHSA-5qvp-pr9f-2g2v

Plugin Details

Severity: High

ID: 439674

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 4/2/2026

Updated: 4/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/1/2026

Vulnerability Publication Date: 4/1/2026

Reference Information

cwe: CWE-377