Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7246

Опубликовано: 30 апр. 2026
Источник: redhat
CVSS3: 7.2
EPSS Низкий

Описание

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

A flaw was found in Pallets Click. This command injection vulnerability, located in the click.edit() function, allows an attacker with an unprivileged account to execute arbitrary operating system (OS) commands. This could lead to unauthorized control over the affected system.

Отчет

A command injection vulnerability exists in the click.edit() function of the Pallets Click library. The filename parameter is not sanitized before being interpolated into a shell command string, allowing an attacker who controls the filename to inject and execute arbitrary OS commands. The root cause is in edit_files(), which wraps the filename in double quotes and passes the resulting string to subprocess.Popen() with shell=True. A filename containing a double-quote character (") can break out of the quoting context and introduce arbitrary shell metacharacters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2python3.11-clickNot affected
Red Hat Ansible Automation Platform 2python3x-clickNot affected
Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-clickFixedRHSA-2026:2476109.06.2026
Red Hat Ansible Automation Platform 2.5 for RHEL 9python3.12-clickFixedRHSA-2026:2476109.06.2026
Red Hat Ansible Automation Platform 2.6 for RHEL 10python-clickFixedRHSA-2026:2476209.06.2026
Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-clickFixedRHSA-2026:2476209.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2464121github.com/pallets/click: Pallets Click: Arbitrary command execution via command injection in click.edit()

EPSS

Процентиль: 56%
0.009
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
3 месяца назад

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

CVSS3: 7.2
nvd
3 месяца назад

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

CVSS3: 7.2
msrc
2 месяца назад

Pallets Click contains a command injection via Unsanitized Filename "click.edit()"

CVSS3: 7.2
debian
3 месяца назад

Pallets Click, versions 8.3.2 and below, contain a command injection v ...

suse-cvrf
около 1 месяца назад

Security update for python-click

EPSS

Процентиль: 56%
0.009
Низкий

7.2 High

CVSS3

Уязвимость CVE-2026-7246