Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86910.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-86910
Upstream
Published
2026-04-30T14:16:36Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-7246 affecting package python-click for versions less than 8.1.7-3
Details

This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below:

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

References

Affected packages

Azure Linux:3 / python-click

Package

Name
python-click
Purl
pkg:rpm/azure-linux/python-click

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.1.7-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86910.json"