Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics opt…
高危 CVSS 7.5
摘要
Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value of this argument to write cache files to arbitrary file system locations. Fixed in Black 26.3.1.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/psf/black/commit/4937fe6cf241139ddbfc16b0bdbb5b422798909d Patch
- https://github.com/psf/black/pull/5038 Issue Tracking
- https://github.com/psf/black/releases/tag/26.3.1 Release Notes
- https://github.com/psf/black/security/advisories/GHSA-3936-cmfr-pm3m Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:13545
- https://access.redhat.com/errata/RHSA-2026:13553
- https://access.redhat.com/security/cve/CVE-2026-32274
- https://bugzilla.redhat.com/show_bug.cgi?id=2447111
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32274.json
- https://github.com/psf/black/commit/ed770ba4dd50c419148a0fca2b43937a7447e1f9
- https://github.com/psf/black/pull/4176
- https://github.com/pypa/advisory-database/tree/main/vulns/black/PYSEC-2026-2121.yaml
时间线
- nvd_ingest NVD