REDHAT-BUG-2464121: Command Injection
Published Apr 30, 2026
·Updated
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Affected Software
1 affected component
pypi/click<=8.3.2
Event History
Apr 30, 2026
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2464121?
The severity of REDHAT-BUG-2464121 is classified as high, rated at 7.
2
How do I fix REDHAT-BUG-2464121?
To fix REDHAT-BUG-2464121, upgrade the Click package to version 8.3.3 or later.
3
What causes the vulnerability in REDHAT-BUG-2464121?
REDHAT-BUG-2464121 is caused by a command injection vulnerability in the click.edit() function.
4
Who is affected by REDHAT-BUG-2464121?
Users of Pallets Click versions 8.3.2 and below are affected by REDHAT-BUG-2464121.
5
What can attackers do with REDHAT-BUG-2464121?
Attackers can exploit REDHAT-BUG-2464121 to execute arbitrary OS commands from an unprivileged account.