CVE-2026-32274

Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value of this argument to write cache files to arbitrary file system locations. Fixed in Black 26.3.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:black:*:*:*:*:*:python:*:*

History

18 Mar 2026, 14:12

Type Values Removed Values Added
References () https://github.com/psf/black/commit/4937fe6cf241139ddbfc16b0bdbb5b422798909d - () https://github.com/psf/black/commit/4937fe6cf241139ddbfc16b0bdbb5b422798909d - Patch
References () https://github.com/psf/black/pull/5038 - () https://github.com/psf/black/pull/5038 - Issue Tracking, Patch
References () https://github.com/psf/black/releases/tag/26.3.1 - () https://github.com/psf/black/releases/tag/26.3.1 - Release Notes
References () https://github.com/psf/black/security/advisories/GHSA-3936-cmfr-pm3m - () https://github.com/psf/black/security/advisories/GHSA-3936-cmfr-pm3m - Vendor Advisory
First Time Python
Python black
Summary
  • (es) Black es el formateador de código Python intransigente. Antes de la versión 26.3.1, Black escribe un archivo de caché, cuyo nombre se calcula a partir de varias opciones de formato. El valor de la opción --python-cell-magics se colocaba en el nombre del archivo sin sanitización, lo que permitía a un atacante que controla el valor de este argumento escribir archivos de caché en ubicaciones arbitrarias del sistema de archivos. Corregido en Black 26.3.1.
CPE cpe:2.3:a:python:black:*:*:*:*:*:python:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

12 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 20:16

Updated : 2026-03-18 14:12


NVD link : CVE-2026-32274

Mitre link : CVE-2026-32274

CVE.ORG link : CVE-2026-32274


JSON object : View

Products Affected

python

  • black
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')