Skip to content

CVE-2026-7246 (High) detected in click-8.1.8-py3-none-any.whl #300

@mend-bolt-for-github

Description

@mend-bolt-for-github

CVE-2026-7246 - High Severity Vulnerability

Vulnerable Library - click-8.1.8-py3-none-any.whl

Composable command line interface toolkit

Library home page: https://files.pythonhosted.org/packages/7e/d4/7ebdbd03970677812aac39c869717059dbb71a4cfc033ca6e5221787892c/click-8.1.8-py3-none-any.whl

Path to dependency file: /OPENAPI-REST-API/swagger-client/python-flask/test-requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260402123536_MTXLIM/python_EKDBTK/20260402123839/click-8.1.8-py3-none-any.whl

Dependency Hierarchy:

  • Flask-Testing-0.8.0.tar.gz (Root Library)
    • flask-3.1.3-py3-none-any.whl
      • click-8.1.8-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 1f70e2feccb7006c8d32cc7d4fe62f5cf5e5c34d

Found in base branch: master

Vulnerability Details

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-04-30

URL: CVE-2026-7246

CVSS 3 Score Details (7.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: High
    • Privileges Required: High
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-30

Fix Resolution: click - 8.3.3,https://github.com/pallets/click.git - 8.3.3,click - 8.3.3


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions