CVE-2026-32274 is a path traversal vulnerability affecting the Python code formatter Black, specifically versions prior to 26.3.1. It allows an attacker to write cache files to arbitrary file system locations by injecting unsanitized input into the --python-cell-magics option. Rated High with a CVSS v3.1 score of 7.5, this vulnerability has a low attack complexity and can be exploited remotely without authentication or user interaction, leading to a high integrity impact. There is currently no evidence of active exploitation, nor are there public exploit modules available. Despite some community discussion and limited media coverage, its very low EPSS score suggests a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.3.1CPE matchmatch criteria | cpe:2.3:a:python:black:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.