From: Tim Orling <[email protected]>

Recipe (PV): python3-click (8.3.1)
Before -> After python:click -> palletsprojects:click
Newly caught: CVE-2026-7246 (command injection in click.edit())
Status: unpatched (fixed 8.3.3)

Note: The original commit targeted python3-click_8.4.2.bb. This is
adjusted for Wrynose, where the recipe version is 8.3.1. The unrelated
DESCRIPTION cleanup from the original commit is intentionally omitted.

AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <[email protected]>
Signed-off-by: Richard Purdie <[email protected]>
(cherry picked from commit 30357a26d7ce490725d1b0ac3375047d00595a5c)
Signed-off-by: Devansh Patel <[email protected]>
---
 meta/recipes-devtools/python/python3-click_8.3.1.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-devtools/python/python3-click_8.3.1.bb 
b/meta/recipes-devtools/python/python3-click_8.3.1.bb
index 1f42fe1a50..49204e96e1 100644
--- a/meta/recipes-devtools/python/python3-click_8.3.1.bb
+++ b/meta/recipes-devtools/python/python3-click_8.3.1.bb
@@ -12,6 +12,8 @@ SRC_URI[sha256sum] = 
"12ff4785d337a1bb490bb7e9c2b1ee5da3112e94a8622f26a6c77f5d2f
 
 inherit pypi python_flit_core ptest-python-pytest
 
+CVE_PRODUCT = "palletsprojects:click"
+
 RDEPENDS:${PN}-ptest += " \
        python3-pytest \
        python3-terminal \
-- 
2.35.6
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243836): 
https://lists.openembedded.org/g/openembedded-core/message/243836
Mute This Topic: https://lists.openembedded.org/mt/120843163/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to