THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-7246 (HIGH 7.2) — This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the cl

[NVD] CVE-2026-7246 (HIGH 7.2) — This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the cl

lownvdPublished 2026-04-30

CVE-2026-7246 CVSS: 7.2 HIGH Published: 2026-04-30T14:16:36.433

This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below:

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitra

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-7246