There is 1 open security issue in trixie.
1 issue left for the package maintainer to handle:
- CVE-2026-7246:
(needs triaging)
This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
You can find information about how to handle this issue in the security team's documentation.