Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-7246

This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 57.0%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-7246


Contact Us

Shodan ® - All rights reserved