CVE-2026-7246: [DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"
Published Apr 30, 2026
·Updated
Pallets Click contains a command injection via Unsanitized Filename "click.edit()"
Other sources
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
— Red Hat
Affected Software
4 affected componentsFixes available
pypi/click<=8.3.2
Microsoft azl3 python-click 8.1.7-2
palletsprojects Click<8.3.3
IBM Concert Software<=1.0.0-2.3.1
Event History
Apr 30, 2026
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionWeakness
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 17, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Aug 27, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-7246?
CVE-2026-7246 has a high severity level due to its potential for command injection attacks.
2
How do I fix CVE-2026-7246?
To fix CVE-2026-7246, upgrade Pallets Click to version 8.3.3 or later.
3
Which versions of Pallets Click are affected by CVE-2026-7246?
Pallets Click versions 8.3.2 and below are affected by CVE-2026-7246.
4
What types of attacks can CVE-2026-7246 enable?
CVE-2026-7246 can enable attackers to execute arbitrary OS commands on the vulnerable system.
5
Is user authentication required to exploit CVE-2026-7246?
No, CVE-2026-7246 can be exploited by attackers using unprivileged accounts.