CVE-2026-7246

Published: May 6, 2026Last modified: May 7, 2026

Description

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

Severity score breakdown

ParameterValue
Base score7.2
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredHIGH
User interactionREQUIRED
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita LinuxStreampy3-clickFixed (8.3.3-r0)

References

ON THIS PAGE