VDB

DEBIAN-CVE-2026-7246

DEBIAN-CVE-2026-7246 PUBLISHED CVSS 7.199999809265137 HIGH

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

Risk Scores

CVSS 3.1
7.199999809265137
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:13python-click0, 8.2.0+0.really.8.1.8
Debian:12python-click8.2.0+0.really.8.1.8, 8.1.8-2, 8.1.8-1
Debian:14python-click8.2.0+0.really.8.1.8, 0
Debian:11python-click8.2.0+0.really.8.1.8, 8.2.0-1, 8.1.8-1

Timeline

  • Apr 30, 2026 CVE Published
  • May 1, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›