White Rabbitx[verified]@TheRabbitPyDisclosure
A critical RCE vulnerability (CVE‑2026‑31900) was disclosed for black <=26.2.0, allowing secret theft via a malicious pyproject.toml; it is patched in version 26.3.0+.
White Rabbitx[verified]@TheRabbitPyDisclosure
The tweet announces the new vulnerability CVE‑2026‑31900, highlights its high CVSS score and command injection vector, but provides no PoC, exploit code, active exploitation evidence, or patch information.
CVE@CVEnewGeneral
The post merely cites the CVE record for Black, the Python formatter, without supplying any technical details, PoC, exploit, or mitigation information.
Infoflowcloud@infoflowcloudGeneral
The snippet references CVE‑2026‑31900 and provides a brief description of the affected tool and a link to its record, but offers no concrete details on exploitation, remediation, or the nature of the vulnerability.
‘BBWriteups’@bbwriteupDisclosure
The post references a Medium article describing CVE‑2026‑31900, a permissive regex vulnerability in psf/black’s GitHub Action that results in remote code execution.