CVE Tracker

CVE-2026-7246 @ Silk

Status
does_not_affect
Priority
5.82
Match score
4.0
Risk
RCE priv:user
CVSS
7.2 HIGH
Reason
cpe: click; pkgs: click; version: in-range: click-8.1.3-2; debian:bookworm python-click open; risk:rce
Created
2026-08-20T17:17:03Z
Updated
2026-08-22T10:15:43Z
Closed
2026-08-20T17:23:47Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
click-8.1.3-2

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Suggestions: click

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
Debian GNU/Linux 12 (bookworm) (12) · debian
Arch
x86_64
kernel_release
uname -r → 6.1.0-52-amd64
kernel_version
uname -v → #1 SMP PREEMPT_DYNAMIC Debian 6.1.180-1 (2026-08-03)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Description

This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below:

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

Determination

Debian’s tracker still labels bookworm 8.1.3-2 as “vulnerable” and <no-dsa>, but that is a conservative catch-all. The vulnerable shell=True quoting path is not in 8.1.3.

Update status

Add note only

Mitigation log

2026-08-20T17:23:47Z — does_not_affect
Debian’s tracker still labels bookworm 8.1.3-2 as “vulnerable” and <no-dsa>, but that is a conservative catch-all. The vulnerable shell=True quoting path is not in 8.1.3.

References

NVD: CVE-2026-7246