7.5

CVE-2026-32274

Black: Arbitrary file writes from unsanitized user input in cache file name

Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value of this argument to write cache files to arbitrary file system locations. Fixed in Black 26.3.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Black SwPlatform python Version < 26.3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.463
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
security-advisories@github.com 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://github.com/psf/black/pull/5038
Patch
Issue Tracking
https://github.com/psf/black/commit/4937fe6cf241139ddbfc16b0bdbb5b422798909d
Patch
https://github.com/psf/black/releases/tag/26.3.1
Release Notes
https://bugzilla.redhat.com/show_bug.cgi?id=2447111
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32274.json
https://access.redhat.com/errata/RHSA-2026:10184
https://access.redhat.com/errata/RHSA-2026:13545
https://access.redhat.com/errata/RHSA-2026:13553
https://github.com/psf/black/security/advisories/GHSA-3936-cmfr-pm3m
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-32274
https://github.com/psf/black/commit/ed770ba4dd50c419148a0fca2b43937a7447e1f9
https://github.com/psf/black/pull/4176
https://github.com/pypa/advisory-database/tree/main/vulns/black/PYSEC-2026-2121.yaml