---
schema_version: '1.0'
id: security-20260714-8d098b
url: https://osv.dev/vulnerability/PYSEC-2026-2132
url_hash: 8d098b4184e70856f5dfb9f70cebfe75a3c414bef0dadcd8843b4c37f9828c30
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-2132
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-7246
- PYSEC-2026-2132
- severity:CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
- click
- PyPI
lang: en
published_at: '2026-04-30T14:16:36Z'
fetched_at: '2026-07-14T06:42:23Z'
updated_at: '2026-07-14T06:43:41Z'
status: published
content_hash: 7697c980762e0059091d7182b15305a522c9ec73c28bbeb4d6246c2a9f717355
license_note: full
summary: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability
  in the click.edit() function, allowing attackers to pass arbitrary OS commands from
  an unprivileged account.
summary_source: rss
summary_en: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability
  in the click.edit() function, allowing attackers to pass arbitrary OS commands from
  an unprivileged account.
entities: []
key_facts: []
related: []
related_auto: []
title: CVE-2026-7246 — click
---

# CVE-2026-7246 — click

## TL;DR
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

## Key Points
- cve / CVE-2026-7246 / PYSEC-2026-2132 / severity:CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H / click / PyPI

## Details
**Severity:** CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
**Advisory:** PYSEC-2026-2132 (CVE-2026-7246)

**Affected (your watchlist):**
- `PyPI:click` 8.3.1 → fixed in 8.3.3 [docker/docker-llmwiki]

**Details:**
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

**References:**
- https://access.redhat.com/security/cve/CVE-2026-7246
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json
- https://access.redhat.com/errata/RHSA-2026:24761
- https://access.redhat.com/errata/RHSA-2026:24762
- https://bugzilla.redhat.com/show_bug.cgi?id=2464121
- https://github.com/pallets/click/releases/tag/8.3.3
- https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-2132_

## Source
元記事: [CVE-2026-7246 — click](https://osv.dev/vulnerability/PYSEC-2026-2132) — published 2026-04-30T14:16:36Z
