Vulnerabilities (CVE)

Filtered by vendor Palletsprojects Subscribe
Filtered by product Click
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-7246 1 Palletsprojects 1 Click 2026-08-18 N/A 7.2 HIGH
This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.