Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
References
Configurations
History
30 Jun 2026, 03:21
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-78 | |
| References |
|
17 Jun 2026, 11:02
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/pallets/click/releases/tag/8.3.3 - Patch, Product |
30 Apr 2026, 16:39
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-30 14:16
Updated : 2026-06-30 03:21
NVD link : CVE-2026-7246
Mitre link : CVE-2026-7246
CVE.ORG link : CVE-2026-7246
JSON object : View
Products Affected
palletsprojects
- click
