CVE-2026-32274·Python vulnerability
Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value of this argument to write cache files to arbitrary file system locations. Fixed in Black 26.3.1.
- Severity
- high
- Software
- Python
- Fixed in
- 26.3.1
- Published
- 2026-03-12
Affected versions
Until: 26.3.1
Fixed in: 26.3.1
How to fix this CVE
Update Black to version 26.3.1 or later to remediate a path traversal vulnerability in the cache file naming mechanism. The --python-cell-magics option was not properly sanitized, allowing attackers to write cache files to arbitrary filesystem locations. Ensure all Python installations using Black for code formatting are patched immediately.
sudo dnf update python3-blackDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check the installed Black version by running: python3 -m pip show black | grep Version
- Step 2: Verify if Black is actively used in your CI/CD pipelines or development environments by searching: grep -r 'black' /etc/systemd/system/ ~/.bashrc ~/.bash_profile
- Step 3: Search system logs for suspicious cache file creation patterns: grep -r 'cache' /var/log/apt/history.log /var/log/dnf.log | grep -i black
- Step 4: Confirm the fix by re-running: python3 -m pip show black | grep Version and verify it reports 26.3.1 or higher
FAQ
What is CVE-2026-32274?
CVE-2026-32274 is a path traversal vulnerability in Black (Python code formatter) versions 24.3.0 through 26.3.0 where unsanitized command-line arguments in the --python-cell-magics option could allow arbitrary cache file writes to the filesystem.
Is CVE-2026-32274 being actively exploited?
No, this vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog and no public exploits are available.
What versions of Python are affected by CVE-2026-32274?
Black versions from 24.3.0 up to and including 26.3.0 are vulnerable; Python itself is not directly affected but Black installations on Python 3.x systems require the update.
How do I check if my server is vulnerable to CVE-2026-32274?
Run: python3 -m pip show black | grep Version and verify the version is below 26.3.1; also check if --python-cell-magics is used in your development or CI workflows.
Does Defensia detect CVE-2026-32274?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Black is installed on a monitored server, CVE-2026-32274 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-32274. Free for 1 server.
Get started free