CVE-2026-7246

EUVD-2026-26375
This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below:

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Command Injection
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 57.6%
Affected Products (NVD)
VendorProductVersion
palletsprojectsclick
𝑥
< 8.3.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:8.3.3-1.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:8.3.3-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 10
0:8.3.3-1.el10ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:8.3.3-1.el9ap ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
python-click
bookworm
no-dsa
bullseye
postponed
forky
8.3.3-2
fixed
sid
8.3.3-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-click
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python3-click
Amazon Linux 2023
0:7.1.2-5.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
python-click
Azure Linux 3.0
0:8.1.7-3.azl3
fixed