CVE-2026-32274Disclosure(python / black)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value of this argument to write cache files to arbitrary file system locations. Fixed in Black 26.3.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • black

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
black

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2Technical Details · 2026-03-12: 203-12
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32274 Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The valu… https://www.cve.org/CVERecord?id=CVE-2026-32274

    Post summary

    The tweet mentions CVE-2026-32274, noting that Black's cache file naming logic before version 26.3.1 may be vulnerable, but it provides no evidence of exploits, PoCs, or mitigations.

    00000337
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32274 Black Python Formatter Cache File Path Traversal Before 26.3.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32274

    Post summary

    The entry points out CVE-2026-32274, a path‑traversal flaw in Black Python Formatter before version 26.3.1, but otherwise offers only a brief description and a link without detailed technical info or mitigation steps.

    0000065
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonblack-python-

Explore more