PT-2026-36098 · Pallets Click+1 · Click
Published
2026-04-30
·
Updated
2026-04-30
·
CVE-2026-7246
CVSS v3.1
7.2
High
| Vector | AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H |
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Click