Back to search
CVE-2026-7246
Published: Apr 30, 2026
Modified: May 7, 2026
PUBLISHED
Description
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
| Vendor | Product | Versions |
|---|---|---|
Pallets Click | Click | affected 0 - < 8.3.3 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now