CVE-2026-7246 @ Silk
Status
does_not_affect
Priority
5.82
Match score
4.0
Risk
RCE
priv:user
CVSS
7.2 HIGH
Reason
cpe: click; pkgs: click; version: in-range: click-8.1.3-2; debian:bookworm python-click open; risk:rce
Created
2026-08-20T17:17:03Z
Updated
2026-08-22T10:15:43Z
Closed
2026-08-20T17:23:47Z
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| click-8.1.3-2 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: click
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
Debian GNU/Linux 12 (bookworm)
(12)
· debian
Arch
x86_64
kernel_release
uname -r → 6.1.0-52-amd64kernel_version
uname -v → #1 SMP PREEMPT_DYNAMIC Debian 6.1.180-1 (2026-08-03)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Description
This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Determination
Debian’s tracker still labels bookworm 8.1.3-2 as “vulnerable” and <no-dsa>, but that is a conservative catch-all. The vulnerable shell=True quoting path is not in 8.1.3.
Update status
Add note only
Mitigation log
2026-08-20T17:23:47Z — does_not_affect
Debian’s tracker still labels bookworm 8.1.3-2 as “vulnerable” and <no-dsa>, but that is a conservative catch-all. The vulnerable shell=True quoting path is not in 8.1.3.
References
- https://github.com/pallets/click/releases/tag/8.3.3
- https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
- https://access.redhat.com/errata/RHSA-2026:24761
- https://access.redhat.com/errata/RHSA-2026:24762
- https://access.redhat.com/security/cve/CVE-2026-7246
- https://bugzilla.redhat.com/show_bug.cgi?id=2464121
- https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json
NVD: CVE-2026-7246