Описание
Security update for python-click
This update for python-click fixes the following issue
- CVE-2026-7246: Arbitrary command execution via command injection in click.edit() (bsc#1263898).
Список пакетов
openSUSE Leap 16.0
python313-click-8.2.1-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1263898
- SUSE CVE CVE-2026-7246 page
Описание
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Затронутые продукты
openSUSE Leap 16.0:python313-click-8.2.1-160000.3.1
Ссылки
- CVE-2026-7246
- SUSE Bug 1263898