CVE-2026-7246

EUVD-2026-26375
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Command Injection
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
palletsprojectsclick
𝑥
< 8.3.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:8.3.3-1.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:8.3.3-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 10
0:8.3.3-1.el10ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:8.3.3-1.el9ap ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
python-click
bookworm
no-dsa
bullseye
postponed
forky
8.3.3-1
fixed
sid
8.3.3-2
fixed
trixie
no-dsa
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python3-click
Amazon Linux 2023
0:7.1.2-5.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
python-click
Azure Linux 3.0
0:8.1.7-3.azl3
fixed