Hello Yoann,

Thanks for the feedback.

The upstream fix and its follow-up are kept as separate patches in v2. Since 
the follow-up is small and self-contained, I have included the backport, as 
shown in [1].

For reference, the NVD record [2] documents the Pallets Click project’s 
position regarding the disputed CVE.

[1] https://lists.openembedded.org/g/openembedded-core/message/246451
[2] https://nvd.nist.gov/vuln/detail/cve-2026-7246

Best regards,
Darsh

On Mon, Sep 21, 2026 at 03:26 PM, Yoann Congal wrote:

> 
> On Mon Sep 7, 2026 at 11:26 AM CEST, Darsh Kelaiya -X (dkelaiya - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> 
>> On Sun, Sep 6, 2026 at 04:46 AM, Yoann Congal wrote:
>> 
>> 
>>> 
>>> On Fri Aug 21, 2026 at 6:32 PM CEST, Darsh Kelaiya -X (dkelaiya - E
>>> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
>>> 
>>> 
>>>> From: Darsh Kelaiya <[email protected]>
>>>> 
>>>> This patch applies the upstream fix for CVE-2026-7246 as referenced
>>>> in [2], using the upstream commit identified in [1].
>>>> 
>>>> The backport also adapts editor regression tests from the upstream
>>>> test and documentation follow-up identified in [3]. This follow-up
>>>> does not contain an additional production security fix.
>>>> 
>>>> [1] 
>>>> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42
>>>> 
>>>> 
>>>> [2] 
>>>> https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
>>>> 
>>>> 
>>>> [3] 
>>>> https://github.com/pallets/click/commit/b55294797ef32e22eb41e7d9657edb8faefa4976
>>>> 
>>>> 
>>>> 
>>>> Signed-off-by: Darsh Kelaiya <[email protected]>
>>>> ---
>>>> .../python/python3-click/CVE-2026-7246.patch | 245 ++++++++++++++++++
>>>> .../python/python3-click_8.1.7.bb | 5 +-
>>>> 2 files changed, 249 insertions(+), 1 deletion(-)
>>>> create mode 100644
>>>> meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch
>>>> 
>>>> diff --git
>>>> a/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch
>>>> b/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch
>>>> new file mode 100644
>>>> index 0000000000..47ee1a551f
>>>> --- /dev/null
>>>> +++ b/meta/recipes-devtools/python/python3-click/CVE-2026-7246.patch
>>>> @@ -0,0 +1,245 @@
>>>> +From cb30f575b1a251e8698909bca2a443d41dad1824 Mon Sep 17 00:00:00 2001
>>>> +From: Kevin Deldycke <[email protected]>
>>>> +Date: Wed, 4 Mar 2026 14:51:58 +0400
>>>> +Subject: [PATCH] Document and fix command string sanitizing with
>>>> `shlex.split`
>>>> +
>>>> +Removes last use of `shell=True` use for command invokation for
>>>> defense-in-depth.
>>>> +Refs: #1026, #1477 and #2775
>>>> +
>>>> +CVE: CVE-2026-7246
>>>> +Upstream-Status: Backport [ 
>>>> https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42
>>>> 
>>>> ]
>>>> +
>>>> +Backport Changes:
>>>> +- Click 8.1.7 uses Editor.edit_file(filename), not the newer
>>>> + Editor.edit_files(filenames) API. Apply the argv-list change
>>>> + to one filename without adding the multi-file API.
>>>> +- Adapt editor tests from b96c2601 and follow-up b5529479 to
>>> 
>>> Hello,
>>> 
>>> This commit has both b96c2601 and b5529479 squashed. Please keep
>>> upstream backport patches split.
>>> 
>>> Can you send a v2 with as the CVE fix (b96c2601) and its followup
>>> (b5529479)?
>>> 
>>> Thanks!
>>> 
>>> --
>>> Yoann Congal
>>> Smile ECS
>> 
>> Hi Yoann,
>> 
>> While preparing v2, I noticed that NVD now marks CVE-2026-7246 as disputed
>> and states that the Pallets Click project does not consider it a valid
>> vulnerability:
>> 
>> https://nvd.nist.gov/vuln/detail/CVE-2026-7246
>> 
>> However, the published advisory identifies upstream commit b96c2601 as the
>> fix:
>> 
>> https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
>> 
>> 
>> Upstream describes the removal of shell=True as defense-in-depth, so I
>> wanted to confirm the preferred handling. Should I replace the backport
>> patches with a status entry such as:
>> 
>> CVE_STATUS[CVE-2026-7246] = "disputed: Pallets Click does not consider
>> this a valid vulnerability"
>> 
>> Or should I continue with the split v2 backport patches as hardening?
> 
> Hello,
> 
> It depends on the patch complexity: If it is small and easely
> understandable let's backport it. If not, we can ignore it but I'd like
> to see the Pallets Click project reasonning for disputing it please.
> 
> Thanks!
> --
> Yoann Congal
> Smile ECS
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246452): 
https://lists.openembedded.org/g/openembedded-core/message/246452
Mute This Topic: https://lists.openembedded.org/mt/120864409/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
      • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
        • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
        • ... Yoann Congal via lists.openembedded.org
          • ... Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org

Reply via email to