<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:55:03 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-7246</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-7246</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: py3-click&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: py3-click&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-7246</guid>
    </item>
    <item>
      <title>BREW-acronym-CVE-2026-7246</title>
      <link>https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-7246</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: acronym&lt;/p&gt;
&lt;p&gt;Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: acronym&lt;/p&gt;
&lt;p&gt;Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-7246</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0834 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834</link>
      <description>certfr-2026-avi-0834</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-DU27033 — Security fixes in apache-superset 5.0.0-r8</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-du27033</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-superset&lt;/p&gt;
&lt;p&gt;Package apache-superset version 5.0.0-r8 fixes 6 vulnerabilities: ghsa-537c-gmf6-5ccf, CVE-2026-34180, ghsa-6v7p-g79w-8964, CVE-2026-57585, CVE-2026-44405...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-superset&lt;/p&gt;
&lt;p&gt;Package apache-superset version 5.0.0-r8 fixes 6 vulnerabilities: ghsa-537c-gmf6-5ccf, CVE-2026-34180, ghsa-6v7p-g79w-8964, CVE-2026-57585, CVE-2026-44405...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-du27033</guid>
    </item>
    <item>
      <title>EUVD-2026-355255</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355255</link>
      <description>EUVD-2026-355255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355255</guid>
    </item>
    <item>
      <title>fkie_cve-2026-7246</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-7246</link>
      <description>&lt;p&gt;This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below:&lt;/p&gt;
&lt;p&gt;Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below:&lt;/p&gt;
&lt;p&gt;Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-7246</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-7246 — Pallets Click contains a command injection via Unsanitized Filename "click.edit()"</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-7246</link>
      <description>msrc_CVE-2026-7246</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-7246</guid>
    </item>
    <item>
      <title>OESA-2026-2302 — python-click security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2302</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-click&lt;/p&gt;
&lt;p&gt;Click is a Python package for creating beautiful command line interfaces in a composable way with as little code as necessary. It&amp;amp;amp;apos;s the &amp;amp;amp;quot;Command Line Interface Creation Kit&amp;amp;amp;quot;. It&amp;amp;amp;apos;s highly configurable but comes with sensible defaults out of the box.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pallets Click, versions 8.3.2 and below, contains a command injection vulnerability in the click.edit() function. The vulnerability allows attackers to inject arbitrary OS commands through unsanitized filename parameters in the click.edit() function. Attackers can exploit this vulnerability to execute malicious commands from an unprivileged account, potentially leading to complete system compromise.(CVE-2026-7246)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-click&lt;/p&gt;
&lt;p&gt;Click is a Python package for creating beautiful command line interfaces in a composable way with as little code as necessary. It&amp;amp;amp;apos;s the &amp;amp;amp;quot;Command Line Interface Creation Kit&amp;amp;amp;quot;. It&amp;amp;amp;apos;s highly configurable but comes with sensible defaults out of the box.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pallets Click, versions 8.3.2 and below, contains a command injection vulnerability in the click.edit() function. The vulnerability allows attackers to inject arbitrary OS commands through unsanitized filename parameters in the click.edit() function. Attackers can exploit this vulnerability to execute malicious commands from an unprivileged account, potentially leading to complete system compromise.(CVE-2026-7246)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2302</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10760-1 — python311-click-8.3.3-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10760-1</link>
      <description>&lt;p&gt;python311-click-8.3.3-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-click-8.3.3-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10760-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2132</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2132</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: click&lt;/p&gt;
&lt;p&gt;Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: click&lt;/p&gt;
&lt;p&gt;Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2132</guid>
    </item>
    <item>
      <title>RHSA-2026:24761 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:24761</link>
      <description>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions github.com/pallets/click: Pallets Click: Arbitrary command execution via command injection in click.edit() minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance Vite: Vite: Information disclosure via WebSocket connection bypasses access control cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions github.com/pallets/click: Pallets Click: Arbitrary command execution via command injection in click.edit() minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance Vite: Vite: Information disclosure via WebSocket connection bypasses access control cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:24761</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22254-1 — Security update for python-click</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22254-1</link>
      <description>&lt;p&gt;Security update for python-click&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-click&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22254-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2026-7246</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-7246</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-click, Ubuntu:18.04:LTS: python-click, Ubuntu:20.04:LTS: python-click, Ubuntu:22.04:LTS: python-click, Ubuntu:24.04:LTS: python-click, Ubuntu:25.10: python-click, Ubuntu:26.04: python-click&lt;/p&gt;
&lt;p&gt;(Pallets Click, versions 8.3.2 and below, contain a command injection v ...)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-click, Ubuntu:18.04:LTS: python-click, Ubuntu:20.04:LTS: python-click, Ubuntu:22.04:LTS: python-click, Ubuntu:24.04:LTS: python-click, Ubuntu:25.10: python-click, Ubuntu:26.04: python-click&lt;/p&gt;
&lt;p&gt;(Pallets Click, versions 8.3.2 and below, contain a command injection v ...)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-7246</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</guid>
    </item>
  </channel>
</rss>
