This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below:
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
References
Configurations
History
No history.
Information
Published : 2026-04-30 14:16
Updated : 2026-08-18 21:18
NVD link : CVE-2026-7246
Mitre link : CVE-2026-7246
CVE.ORG link : CVE-2026-7246
JSON object : View
Products Affected
palletsprojects
- click
