OESA-2026-4064

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-4064
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-4064.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-4064
Upstream
Published
2026-09-25T01:27:57Z
Modified
2026-09-25T01:45:12Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
python-black security update
Details

The uncompromising code formatter

Security Fix(es):

Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value of this argument to write cache files to arbitrary file system locations. Fixed in Black 26.3.1.(CVE-2026-32274)

Database specific
{
    "severity":  "High"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / python-black

Package

Name
python-black
Purl
pkg:rpm/openEuler/python-black&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
24.2.0-3.oe2403sp3

Ecosystem specific

{
    "noarch":  [
        "python3-black-24.2.0-3.oe2403sp3.noarch.rpm"
    ],
    "src":  [
        "python-black-24.2.0-3.oe2403sp3.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-4064.json"