Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Thu, 30 Apr 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account. | |
| Title | Pallets Click contains a command injection via Unsanitized Filename "click.edit()" | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-04-30T13:40:48.226Z
Reserved: 2026-04-27T17:37:48.878Z
Link: CVE-2026-7246
Updated: 2026-04-30T13:38:01.428Z
Status : Awaiting Analysis
Published: 2026-04-30T14:16:36.433
Modified: 2026-04-30T15:09:49.123
Link: CVE-2026-7246
No data.
OpenCVE Enrichment
No data.