CVE-2026-7246 PUBLISHED

Pallets Click contains a command injection via Unsanitized Filename "click.edit()"

Assigner: certcc
Reserved: 27.04.2026 Published: 30.04.2026 Updated: 30.04.2026

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

Product Status

Vendor Pallets Click
Product Click
Versions
  • affected from 0 to 8.3.3 (excl.)

References

Problem Types

  • CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')