Unpin click to remediate CVE-2026-7246 - #78

Open
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection
Open

Unpin click to remediate CVE-2026-7246#78
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection

Conversation

@RyanL1997

Copy link
Copy Markdown

Description

Replaces the exact click == 7.1.2 pin in setup.py with a version requirement that admits the CVE-2026-7246 fix.

CVE-2026-7246 (High, CVSS 7.2) is a command injection in click.edit(), affecting click <= 8.3.2 and fixed in 8.3.3.

Two things are wrong with the current pin:

  1. It installs a vulnerable click.
  2. Because it is an exact pin, it also forces the vulnerable version back into any environment that installs this package next to a patched click.

Point 2 is the one that reaches beyond this repo. opensearch-project/sql's doctest bootstrap clones this branch and installs it right after its own requirements:

$DIR/.venv/bin/pip install -r $DIR/requirements.txt # click 8.x$DIR/.venv/bin/pip install -e ./sql-cli # <-- drags click back to 7.1.2

So the pending remediation there (opensearch-project/sql#5471) cannot actually take effect until this branch is unpinned.

Why environment markers instead of click >= 8.3.3

The patched release is only published for Python >= 3.10 (every click >= 8.2 sets Requires-Python >= 3.10), while this branch still supports Python 3.9. Requiring 8.3.3 unconditionally makes the package uninstallable on 3.9:

ERROR: Ignored the following versions that require a different python version: ... 8.3.3 Requires-Python >=3.10
ERROR: No matching distribution found for click==8.3.3

So the requirement is split by marker — interpreters that can take the fix are required to, and 3.9 resolves to the newest release available to it:

'click >= 8.3.3; python_version >= "3.10"',
'click >= 8.1.8, < 8.2; python_version < "3.10"',

Worth stating plainly: on Python 3.9 this lands on click 8.1.8, which is still inside the CVE's affected range, because upstream never backported the fix to a 3.9-compatible release. There is no version constraint that fixes 3.9 — that requires either moving off Python 3.9 or dropping the click dependency. This change fixes every interpreter that can be fixed and, more importantly, stops this package from downgrading click for consumers that are already on 3.10+.

Exploitability here

click.edit() is not called anywhere in this package (the click surface used is command/option/argument/echo/secho/confirm/echo_via_pager/Path/STRING/INT). This is supply-chain hygiene and a downstream unblock, not a live vulnerability in the CLI.

Issues Resolved

Unblocks opensearch-project/sql#5445 and opensearch-project/sql#5471.

Note that #5471 needs a companion change: it currently pins click==8.3.3 flat in doctest/requirements.txt, which fails to resolve on the Linux CI image (Python 3.9) and aborts the whole install, taking zc.customdoctests with it — that is the actual cause of its red build-linux (…, doc) checks, and it needs the same marker treatment (or a CI Python bump).

Testing

Verified locally on Python 3.9.6 (same minor version as the sql Linux doctest image):

  • Downgrade is gone — with click 8.1.8 already present, pip install -e . previously reinstalled 7.1.2; it now leaves 8.1.8 in place.
  • Test suitepytest tests/25 passed, 5 skipped, identical to the click 7.1.2 baseline (no new failures, same skips).
  • CLI smoke testopensearchsql --help renders correctly under click 8.
  • Downstream imports — the symbols sql's doctest/test_docs.py imports (Formatter, OpenSearchConnection, OutputSettings) all import cleanly under click 8.
  • Marker resolution — evaluated via packaging.requirements: 3.9 selects click<8.2,>=8.1.8; 3.10 and 3.12 select click>=8.3.3.

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

sql-cli 1.0-legacy pinned `click == 7.1.2` exactly. That pin is vulnerable
to CVE-2026-7246 (command injection in `click.edit()`), and because it is an
exact pin it also forces the vulnerable version back into any environment
that installs this package alongside a patched click.
This is what blocks opensearch-project/sql#5471: the doctest bootstrap runs
`pip install -r requirements.txt` followed by `pip install -e ./sql-cli`, so
sql-cli's pin downgrades click again in the second step.
The fix (click 8.3.3) is only published for Python >= 3.10, while this branch
still supports Python 3.9, so the requirement is expressed with environment
markers: interpreters that can take the patched release require it, and older
ones resolve to the newest version available to them.
`click.edit()` is not used anywhere in this package, so there is no
exploitable path here; this is supply-chain hygiene and unblocks the
downstream remediation.
Verified on Python 3.9.6:
- `pip install -e .` no longer downgrades click (stays at 8.1.8)
- full test suite: 25 passed, 5 skipped -- identical to the click 7.1.2 baseline
- `opensearchsql --help` and the doctest driver imports still work
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@dai-chen

Copy link
Copy Markdown
Collaborator

Shall we merge the commit SHA fix and get CI pass?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@RyanL1997@dai-chen@Swiddis
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Unpin click to remediate CVE-2026-7246 - #78

Open
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection
Open

Unpin click to remediate CVE-2026-7246#78
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection

Conversation

@RyanL1997

Copy link
Copy Markdown

Description

Replaces the exact click == 7.1.2 pin in setup.py with a version requirement that admits the CVE-2026-7246 fix.

CVE-2026-7246 (High, CVSS 7.2) is a command injection in click.edit(), affecting click <= 8.3.2 and fixed in 8.3.3.

Two things are wrong with the current pin:

  1. It installs a vulnerable click.
  2. Because it is an exact pin, it also forces the vulnerable version back into any environment that installs this package next to a patched click.

Point 2 is the one that reaches beyond this repo. opensearch-project/sql's doctest bootstrap clones this branch and installs it right after its own requirements:

$DIR/.venv/bin/pip install -r $DIR/requirements.txt # click 8.x$DIR/.venv/bin/pip install -e ./sql-cli # <-- drags click back to 7.1.2

So the pending remediation there (opensearch-project/sql#5471) cannot actually take effect until this branch is unpinned.

Why environment markers instead of click >= 8.3.3

The patched release is only published for Python >= 3.10 (every click >= 8.2 sets Requires-Python >= 3.10), while this branch still supports Python 3.9. Requiring 8.3.3 unconditionally makes the package uninstallable on 3.9:

ERROR: Ignored the following versions that require a different python version: ... 8.3.3 Requires-Python >=3.10
ERROR: No matching distribution found for click==8.3.3

So the requirement is split by marker — interpreters that can take the fix are required to, and 3.9 resolves to the newest release available to it:

'click >= 8.3.3; python_version >= "3.10"',
'click >= 8.1.8, < 8.2; python_version < "3.10"',

Worth stating plainly: on Python 3.9 this lands on click 8.1.8, which is still inside the CVE's affected range, because upstream never backported the fix to a 3.9-compatible release. There is no version constraint that fixes 3.9 — that requires either moving off Python 3.9 or dropping the click dependency. This change fixes every interpreter that can be fixed and, more importantly, stops this package from downgrading click for consumers that are already on 3.10+.

Exploitability here

click.edit() is not called anywhere in this package (the click surface used is command/option/argument/echo/secho/confirm/echo_via_pager/Path/STRING/INT). This is supply-chain hygiene and a downstream unblock, not a live vulnerability in the CLI.

Issues Resolved

Unblocks opensearch-project/sql#5445 and opensearch-project/sql#5471.

Note that #5471 needs a companion change: it currently pins click==8.3.3 flat in doctest/requirements.txt, which fails to resolve on the Linux CI image (Python 3.9) and aborts the whole install, taking zc.customdoctests with it — that is the actual cause of its red build-linux (…, doc) checks, and it needs the same marker treatment (or a CI Python bump).

Testing

Verified locally on Python 3.9.6 (same minor version as the sql Linux doctest image):

  • Downgrade is gone — with click 8.1.8 already present, pip install -e . previously reinstalled 7.1.2; it now leaves 8.1.8 in place.
  • Test suitepytest tests/25 passed, 5 skipped, identical to the click 7.1.2 baseline (no new failures, same skips).
  • CLI smoke testopensearchsql --help renders correctly under click 8.
  • Downstream imports — the symbols sql's doctest/test_docs.py imports (Formatter, OpenSearchConnection, OutputSettings) all import cleanly under click 8.
  • Marker resolution — evaluated via packaging.requirements: 3.9 selects click<8.2,>=8.1.8; 3.10 and 3.12 select click>=8.3.3.

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

sql-cli 1.0-legacy pinned `click == 7.1.2` exactly. That pin is vulnerable
to CVE-2026-7246 (command injection in `click.edit()`), and because it is an
exact pin it also forces the vulnerable version back into any environment
that installs this package alongside a patched click.
This is what blocks opensearch-project/sql#5471: the doctest bootstrap runs
`pip install -r requirements.txt` followed by `pip install -e ./sql-cli`, so
sql-cli's pin downgrades click again in the second step.
The fix (click 8.3.3) is only published for Python >= 3.10, while this branch
still supports Python 3.9, so the requirement is expressed with environment
markers: interpreters that can take the patched release require it, and older
ones resolve to the newest version available to them.
`click.edit()` is not used anywhere in this package, so there is no
exploitable path here; this is supply-chain hygiene and unblocks the
downstream remediation.
Verified on Python 3.9.6:
- `pip install -e .` no longer downgrades click (stays at 8.1.8)
- full test suite: 25 passed, 5 skipped -- identical to the click 7.1.2 baseline
- `opensearchsql --help` and the doctest driver imports still work
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@dai-chen

Copy link
Copy Markdown
Collaborator

Shall we merge the commit SHA fix and get CI pass?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@RyanL1997@dai-chen@Swiddis
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Unpin click to remediate CVE-2026-7246 - #78

Open
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection
Open

Unpin click to remediate CVE-2026-7246#78
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection

Conversation

@RyanL1997

Copy link
Copy Markdown

Description

Replaces the exact click == 7.1.2 pin in setup.py with a version requirement that admits the CVE-2026-7246 fix.

CVE-2026-7246 (High, CVSS 7.2) is a command injection in click.edit(), affecting click <= 8.3.2 and fixed in 8.3.3.

Two things are wrong with the current pin:

  1. It installs a vulnerable click.
  2. Because it is an exact pin, it also forces the vulnerable version back into any environment that installs this package next to a patched click.

Point 2 is the one that reaches beyond this repo. opensearch-project/sql's doctest bootstrap clones this branch and installs it right after its own requirements:

$DIR/.venv/bin/pip install -r $DIR/requirements.txt # click 8.x$DIR/.venv/bin/pip install -e ./sql-cli # <-- drags click back to 7.1.2

So the pending remediation there (opensearch-project/sql#5471) cannot actually take effect until this branch is unpinned.

Why environment markers instead of click >= 8.3.3

The patched release is only published for Python >= 3.10 (every click >= 8.2 sets Requires-Python >= 3.10), while this branch still supports Python 3.9. Requiring 8.3.3 unconditionally makes the package uninstallable on 3.9:

ERROR: Ignored the following versions that require a different python version: ... 8.3.3 Requires-Python >=3.10
ERROR: No matching distribution found for click==8.3.3

So the requirement is split by marker — interpreters that can take the fix are required to, and 3.9 resolves to the newest release available to it:

'click >= 8.3.3; python_version >= "3.10"',
'click >= 8.1.8, < 8.2; python_version < "3.10"',

Worth stating plainly: on Python 3.9 this lands on click 8.1.8, which is still inside the CVE's affected range, because upstream never backported the fix to a 3.9-compatible release. There is no version constraint that fixes 3.9 — that requires either moving off Python 3.9 or dropping the click dependency. This change fixes every interpreter that can be fixed and, more importantly, stops this package from downgrading click for consumers that are already on 3.10+.

Exploitability here

click.edit() is not called anywhere in this package (the click surface used is command/option/argument/echo/secho/confirm/echo_via_pager/Path/STRING/INT). This is supply-chain hygiene and a downstream unblock, not a live vulnerability in the CLI.

Issues Resolved

Unblocks opensearch-project/sql#5445 and opensearch-project/sql#5471.

Note that #5471 needs a companion change: it currently pins click==8.3.3 flat in doctest/requirements.txt, which fails to resolve on the Linux CI image (Python 3.9) and aborts the whole install, taking zc.customdoctests with it — that is the actual cause of its red build-linux (…, doc) checks, and it needs the same marker treatment (or a CI Python bump).

Testing

Verified locally on Python 3.9.6 (same minor version as the sql Linux doctest image):

  • Downgrade is gone — with click 8.1.8 already present, pip install -e . previously reinstalled 7.1.2; it now leaves 8.1.8 in place.
  • Test suitepytest tests/25 passed, 5 skipped, identical to the click 7.1.2 baseline (no new failures, same skips).
  • CLI smoke testopensearchsql --help renders correctly under click 8.
  • Downstream imports — the symbols sql's doctest/test_docs.py imports (Formatter, OpenSearchConnection, OutputSettings) all import cleanly under click 8.
  • Marker resolution — evaluated via packaging.requirements: 3.9 selects click<8.2,>=8.1.8; 3.10 and 3.12 select click>=8.3.3.

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

sql-cli 1.0-legacy pinned `click == 7.1.2` exactly. That pin is vulnerable
to CVE-2026-7246 (command injection in `click.edit()`), and because it is an
exact pin it also forces the vulnerable version back into any environment
that installs this package alongside a patched click.
This is what blocks opensearch-project/sql#5471: the doctest bootstrap runs
`pip install -r requirements.txt` followed by `pip install -e ./sql-cli`, so
sql-cli's pin downgrades click again in the second step.
The fix (click 8.3.3) is only published for Python >= 3.10, while this branch
still supports Python 3.9, so the requirement is expressed with environment
markers: interpreters that can take the patched release require it, and older
ones resolve to the newest version available to them.
`click.edit()` is not used anywhere in this package, so there is no
exploitable path here; this is supply-chain hygiene and unblocks the
downstream remediation.
Verified on Python 3.9.6:
- `pip install -e .` no longer downgrades click (stays at 8.1.8)
- full test suite: 25 passed, 5 skipped -- identical to the click 7.1.2 baseline
- `opensearchsql --help` and the doctest driver imports still work
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@dai-chen

Copy link
Copy Markdown
Collaborator

Shall we merge the commit SHA fix and get CI pass?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@RyanL1997@dai-chen@Swiddis
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Unpin click to remediate CVE-2026-7246 - #78

Open
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection
Open

Unpin click to remediate CVE-2026-7246#78
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection

Conversation

@RyanL1997

Copy link
Copy Markdown

Description

Replaces the exact click == 7.1.2 pin in setup.py with a version requirement that admits the CVE-2026-7246 fix.

CVE-2026-7246 (High, CVSS 7.2) is a command injection in click.edit(), affecting click <= 8.3.2 and fixed in 8.3.3.

Two things are wrong with the current pin:

  1. It installs a vulnerable click.
  2. Because it is an exact pin, it also forces the vulnerable version back into any environment that installs this package next to a patched click.

Point 2 is the one that reaches beyond this repo. opensearch-project/sql's doctest bootstrap clones this branch and installs it right after its own requirements:

$DIR/.venv/bin/pip install -r $DIR/requirements.txt # click 8.x$DIR/.venv/bin/pip install -e ./sql-cli # <-- drags click back to 7.1.2

So the pending remediation there (opensearch-project/sql#5471) cannot actually take effect until this branch is unpinned.

Why environment markers instead of click >= 8.3.3

The patched release is only published for Python >= 3.10 (every click >= 8.2 sets Requires-Python >= 3.10), while this branch still supports Python 3.9. Requiring 8.3.3 unconditionally makes the package uninstallable on 3.9:

ERROR: Ignored the following versions that require a different python version: ... 8.3.3 Requires-Python >=3.10
ERROR: No matching distribution found for click==8.3.3

So the requirement is split by marker — interpreters that can take the fix are required to, and 3.9 resolves to the newest release available to it:

'click >= 8.3.3; python_version >= "3.10"',
'click >= 8.1.8, < 8.2; python_version < "3.10"',

Worth stating plainly: on Python 3.9 this lands on click 8.1.8, which is still inside the CVE's affected range, because upstream never backported the fix to a 3.9-compatible release. There is no version constraint that fixes 3.9 — that requires either moving off Python 3.9 or dropping the click dependency. This change fixes every interpreter that can be fixed and, more importantly, stops this package from downgrading click for consumers that are already on 3.10+.

Exploitability here

click.edit() is not called anywhere in this package (the click surface used is command/option/argument/echo/secho/confirm/echo_via_pager/Path/STRING/INT). This is supply-chain hygiene and a downstream unblock, not a live vulnerability in the CLI.

Issues Resolved

Unblocks opensearch-project/sql#5445 and opensearch-project/sql#5471.

Note that #5471 needs a companion change: it currently pins click==8.3.3 flat in doctest/requirements.txt, which fails to resolve on the Linux CI image (Python 3.9) and aborts the whole install, taking zc.customdoctests with it — that is the actual cause of its red build-linux (…, doc) checks, and it needs the same marker treatment (or a CI Python bump).

Testing

Verified locally on Python 3.9.6 (same minor version as the sql Linux doctest image):

  • Downgrade is gone — with click 8.1.8 already present, pip install -e . previously reinstalled 7.1.2; it now leaves 8.1.8 in place.
  • Test suitepytest tests/25 passed, 5 skipped, identical to the click 7.1.2 baseline (no new failures, same skips).
  • CLI smoke testopensearchsql --help renders correctly under click 8.
  • Downstream imports — the symbols sql's doctest/test_docs.py imports (Formatter, OpenSearchConnection, OutputSettings) all import cleanly under click 8.
  • Marker resolution — evaluated via packaging.requirements: 3.9 selects click<8.2,>=8.1.8; 3.10 and 3.12 select click>=8.3.3.

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

sql-cli 1.0-legacy pinned `click == 7.1.2` exactly. That pin is vulnerable
to CVE-2026-7246 (command injection in `click.edit()`), and because it is an
exact pin it also forces the vulnerable version back into any environment
that installs this package alongside a patched click.
This is what blocks opensearch-project/sql#5471: the doctest bootstrap runs
`pip install -r requirements.txt` followed by `pip install -e ./sql-cli`, so
sql-cli's pin downgrades click again in the second step.
The fix (click 8.3.3) is only published for Python >= 3.10, while this branch
still supports Python 3.9, so the requirement is expressed with environment
markers: interpreters that can take the patched release require it, and older
ones resolve to the newest version available to them.
`click.edit()` is not used anywhere in this package, so there is no
exploitable path here; this is supply-chain hygiene and unblocks the
downstream remediation.
Verified on Python 3.9.6:
- `pip install -e .` no longer downgrades click (stays at 8.1.8)
- full test suite: 25 passed, 5 skipped -- identical to the click 7.1.2 baseline
- `opensearchsql --help` and the doctest driver imports still work
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@dai-chen

Copy link
Copy Markdown
Collaborator

Shall we merge the commit SHA fix and get CI pass?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@RyanL1997@dai-chen@Swiddis
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Unpin click to remediate CVE-2026-7246 - #78

Open
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection
Open

Unpin click to remediate CVE-2026-7246#78
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection

Conversation

@RyanL1997

Copy link
Copy Markdown

Description

Replaces the exact click == 7.1.2 pin in setup.py with a version requirement that admits the CVE-2026-7246 fix.

CVE-2026-7246 (High, CVSS 7.2) is a command injection in click.edit(), affecting click <= 8.3.2 and fixed in 8.3.3.

Two things are wrong with the current pin:

  1. It installs a vulnerable click.
  2. Because it is an exact pin, it also forces the vulnerable version back into any environment that installs this package next to a patched click.

Point 2 is the one that reaches beyond this repo. opensearch-project/sql's doctest bootstrap clones this branch and installs it right after its own requirements:

$DIR/.venv/bin/pip install -r $DIR/requirements.txt # click 8.x$DIR/.venv/bin/pip install -e ./sql-cli # <-- drags click back to 7.1.2

So the pending remediation there (opensearch-project/sql#5471) cannot actually take effect until this branch is unpinned.

Why environment markers instead of click >= 8.3.3

The patched release is only published for Python >= 3.10 (every click >= 8.2 sets Requires-Python >= 3.10), while this branch still supports Python 3.9. Requiring 8.3.3 unconditionally makes the package uninstallable on 3.9:

ERROR: Ignored the following versions that require a different python version: ... 8.3.3 Requires-Python >=3.10
ERROR: No matching distribution found for click==8.3.3

So the requirement is split by marker — interpreters that can take the fix are required to, and 3.9 resolves to the newest release available to it:

'click >= 8.3.3; python_version >= "3.10"',
'click >= 8.1.8, < 8.2; python_version < "3.10"',

Worth stating plainly: on Python 3.9 this lands on click 8.1.8, which is still inside the CVE's affected range, because upstream never backported the fix to a 3.9-compatible release. There is no version constraint that fixes 3.9 — that requires either moving off Python 3.9 or dropping the click dependency. This change fixes every interpreter that can be fixed and, more importantly, stops this package from downgrading click for consumers that are already on 3.10+.

Exploitability here

click.edit() is not called anywhere in this package (the click surface used is command/option/argument/echo/secho/confirm/echo_via_pager/Path/STRING/INT). This is supply-chain hygiene and a downstream unblock, not a live vulnerability in the CLI.

Issues Resolved

Unblocks opensearch-project/sql#5445 and opensearch-project/sql#5471.

Note that #5471 needs a companion change: it currently pins click==8.3.3 flat in doctest/requirements.txt, which fails to resolve on the Linux CI image (Python 3.9) and aborts the whole install, taking zc.customdoctests with it — that is the actual cause of its red build-linux (…, doc) checks, and it needs the same marker treatment (or a CI Python bump).

Testing

Verified locally on Python 3.9.6 (same minor version as the sql Linux doctest image):

  • Downgrade is gone — with click 8.1.8 already present, pip install -e . previously reinstalled 7.1.2; it now leaves 8.1.8 in place.
  • Test suitepytest tests/25 passed, 5 skipped, identical to the click 7.1.2 baseline (no new failures, same skips).
  • CLI smoke testopensearchsql --help renders correctly under click 8.
  • Downstream imports — the symbols sql's doctest/test_docs.py imports (Formatter, OpenSearchConnection, OutputSettings) all import cleanly under click 8.
  • Marker resolution — evaluated via packaging.requirements: 3.9 selects click<8.2,>=8.1.8; 3.10 and 3.12 select click>=8.3.3.

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

sql-cli 1.0-legacy pinned `click == 7.1.2` exactly. That pin is vulnerable
to CVE-2026-7246 (command injection in `click.edit()`), and because it is an
exact pin it also forces the vulnerable version back into any environment
that installs this package alongside a patched click.
This is what blocks opensearch-project/sql#5471: the doctest bootstrap runs
`pip install -r requirements.txt` followed by `pip install -e ./sql-cli`, so
sql-cli's pin downgrades click again in the second step.
The fix (click 8.3.3) is only published for Python >= 3.10, while this branch
still supports Python 3.9, so the requirement is expressed with environment
markers: interpreters that can take the patched release require it, and older
ones resolve to the newest version available to them.
`click.edit()` is not used anywhere in this package, so there is no
exploitable path here; this is supply-chain hygiene and unblocks the
downstream remediation.
Verified on Python 3.9.6:
- `pip install -e .` no longer downgrades click (stays at 8.1.8)
- full test suite: 25 passed, 5 skipped -- identical to the click 7.1.2 baseline
- `opensearchsql --help` and the doctest driver imports still work
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@dai-chen

Copy link
Copy Markdown
Collaborator

Shall we merge the commit SHA fix and get CI pass?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@RyanL1997@dai-chen@Swiddis
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Unpin click to remediate CVE-2026-7246 - #78

Open
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection
Open

Unpin click to remediate CVE-2026-7246#78
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection

Conversation

@RyanL1997

Copy link
Copy Markdown

Description

Replaces the exact click == 7.1.2 pin in setup.py with a version requirement that admits the CVE-2026-7246 fix.

CVE-2026-7246 (High, CVSS 7.2) is a command injection in click.edit(), affecting click <= 8.3.2 and fixed in 8.3.3.

Two things are wrong with the current pin:

  1. It installs a vulnerable click.
  2. Because it is an exact pin, it also forces the vulnerable version back into any environment that installs this package next to a patched click.

Point 2 is the one that reaches beyond this repo. opensearch-project/sql's doctest bootstrap clones this branch and installs it right after its own requirements:

$DIR/.venv/bin/pip install -r $DIR/requirements.txt # click 8.x$DIR/.venv/bin/pip install -e ./sql-cli # <-- drags click back to 7.1.2

So the pending remediation there (opensearch-project/sql#5471) cannot actually take effect until this branch is unpinned.

Why environment markers instead of click >= 8.3.3

The patched release is only published for Python >= 3.10 (every click >= 8.2 sets Requires-Python >= 3.10), while this branch still supports Python 3.9. Requiring 8.3.3 unconditionally makes the package uninstallable on 3.9:

ERROR: Ignored the following versions that require a different python version: ... 8.3.3 Requires-Python >=3.10
ERROR: No matching distribution found for click==8.3.3

So the requirement is split by marker — interpreters that can take the fix are required to, and 3.9 resolves to the newest release available to it:

'click >= 8.3.3; python_version >= "3.10"',
'click >= 8.1.8, < 8.2; python_version < "3.10"',

Worth stating plainly: on Python 3.9 this lands on click 8.1.8, which is still inside the CVE's affected range, because upstream never backported the fix to a 3.9-compatible release. There is no version constraint that fixes 3.9 — that requires either moving off Python 3.9 or dropping the click dependency. This change fixes every interpreter that can be fixed and, more importantly, stops this package from downgrading click for consumers that are already on 3.10+.

Exploitability here

click.edit() is not called anywhere in this package (the click surface used is command/option/argument/echo/secho/confirm/echo_via_pager/Path/STRING/INT). This is supply-chain hygiene and a downstream unblock, not a live vulnerability in the CLI.

Issues Resolved

Unblocks opensearch-project/sql#5445 and opensearch-project/sql#5471.

Note that #5471 needs a companion change: it currently pins click==8.3.3 flat in doctest/requirements.txt, which fails to resolve on the Linux CI image (Python 3.9) and aborts the whole install, taking zc.customdoctests with it — that is the actual cause of its red build-linux (…, doc) checks, and it needs the same marker treatment (or a CI Python bump).

Testing

Verified locally on Python 3.9.6 (same minor version as the sql Linux doctest image):

  • Downgrade is gone — with click 8.1.8 already present, pip install -e . previously reinstalled 7.1.2; it now leaves 8.1.8 in place.
  • Test suitepytest tests/25 passed, 5 skipped, identical to the click 7.1.2 baseline (no new failures, same skips).
  • CLI smoke testopensearchsql --help renders correctly under click 8.
  • Downstream imports — the symbols sql's doctest/test_docs.py imports (Formatter, OpenSearchConnection, OutputSettings) all import cleanly under click 8.
  • Marker resolution — evaluated via packaging.requirements: 3.9 selects click<8.2,>=8.1.8; 3.10 and 3.12 select click>=8.3.3.

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

sql-cli 1.0-legacy pinned `click == 7.1.2` exactly. That pin is vulnerable
to CVE-2026-7246 (command injection in `click.edit()`), and because it is an
exact pin it also forces the vulnerable version back into any environment
that installs this package alongside a patched click.
This is what blocks opensearch-project/sql#5471: the doctest bootstrap runs
`pip install -r requirements.txt` followed by `pip install -e ./sql-cli`, so
sql-cli's pin downgrades click again in the second step.
The fix (click 8.3.3) is only published for Python >= 3.10, while this branch
still supports Python 3.9, so the requirement is expressed with environment
markers: interpreters that can take the patched release require it, and older
ones resolve to the newest version available to them.
`click.edit()` is not used anywhere in this package, so there is no
exploitable path here; this is supply-chain hygiene and unblocks the
downstream remediation.
Verified on Python 3.9.6:
- `pip install -e .` no longer downgrades click (stays at 8.1.8)
- full test suite: 25 passed, 5 skipped -- identical to the click 7.1.2 baseline
- `opensearchsql --help` and the doctest driver imports still work
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@dai-chen

Copy link
Copy Markdown
Collaborator

Shall we merge the commit SHA fix and get CI pass?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@RyanL1997@dai-chen@Swiddis
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Unpin click to remediate CVE-2026-7246 - #78

Open
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection
Open

Unpin click to remediate CVE-2026-7246#78
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection

Conversation

@RyanL1997

Copy link
Copy Markdown

Description

Replaces the exact click == 7.1.2 pin in setup.py with a version requirement that admits the CVE-2026-7246 fix.

CVE-2026-7246 (High, CVSS 7.2) is a command injection in click.edit(), affecting click <= 8.3.2 and fixed in 8.3.3.

Two things are wrong with the current pin:

  1. It installs a vulnerable click.
  2. Because it is an exact pin, it also forces the vulnerable version back into any environment that installs this package next to a patched click.

Point 2 is the one that reaches beyond this repo. opensearch-project/sql's doctest bootstrap clones this branch and installs it right after its own requirements:

$DIR/.venv/bin/pip install -r $DIR/requirements.txt # click 8.x$DIR/.venv/bin/pip install -e ./sql-cli # <-- drags click back to 7.1.2

So the pending remediation there (opensearch-project/sql#5471) cannot actually take effect until this branch is unpinned.

Why environment markers instead of click >= 8.3.3

The patched release is only published for Python >= 3.10 (every click >= 8.2 sets Requires-Python >= 3.10), while this branch still supports Python 3.9. Requiring 8.3.3 unconditionally makes the package uninstallable on 3.9:

ERROR: Ignored the following versions that require a different python version: ... 8.3.3 Requires-Python >=3.10
ERROR: No matching distribution found for click==8.3.3

So the requirement is split by marker — interpreters that can take the fix are required to, and 3.9 resolves to the newest release available to it:

'click >= 8.3.3; python_version >= "3.10"',
'click >= 8.1.8, < 8.2; python_version < "3.10"',

Worth stating plainly: on Python 3.9 this lands on click 8.1.8, which is still inside the CVE's affected range, because upstream never backported the fix to a 3.9-compatible release. There is no version constraint that fixes 3.9 — that requires either moving off Python 3.9 or dropping the click dependency. This change fixes every interpreter that can be fixed and, more importantly, stops this package from downgrading click for consumers that are already on 3.10+.

Exploitability here

click.edit() is not called anywhere in this package (the click surface used is command/option/argument/echo/secho/confirm/echo_via_pager/Path/STRING/INT). This is supply-chain hygiene and a downstream unblock, not a live vulnerability in the CLI.

Issues Resolved

Unblocks opensearch-project/sql#5445 and opensearch-project/sql#5471.

Note that #5471 needs a companion change: it currently pins click==8.3.3 flat in doctest/requirements.txt, which fails to resolve on the Linux CI image (Python 3.9) and aborts the whole install, taking zc.customdoctests with it — that is the actual cause of its red build-linux (…, doc) checks, and it needs the same marker treatment (or a CI Python bump).

Testing

Verified locally on Python 3.9.6 (same minor version as the sql Linux doctest image):

  • Downgrade is gone — with click 8.1.8 already present, pip install -e . previously reinstalled 7.1.2; it now leaves 8.1.8 in place.
  • Test suitepytest tests/25 passed, 5 skipped, identical to the click 7.1.2 baseline (no new failures, same skips).
  • CLI smoke testopensearchsql --help renders correctly under click 8.
  • Downstream imports — the symbols sql's doctest/test_docs.py imports (Formatter, OpenSearchConnection, OutputSettings) all import cleanly under click 8.
  • Marker resolution — evaluated via packaging.requirements: 3.9 selects click<8.2,>=8.1.8; 3.10 and 3.12 select click>=8.3.3.

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

sql-cli 1.0-legacy pinned `click == 7.1.2` exactly. That pin is vulnerable
to CVE-2026-7246 (command injection in `click.edit()`), and because it is an
exact pin it also forces the vulnerable version back into any environment
that installs this package alongside a patched click.
This is what blocks opensearch-project/sql#5471: the doctest bootstrap runs
`pip install -r requirements.txt` followed by `pip install -e ./sql-cli`, so
sql-cli's pin downgrades click again in the second step.
The fix (click 8.3.3) is only published for Python >= 3.10, while this branch
still supports Python 3.9, so the requirement is expressed with environment
markers: interpreters that can take the patched release require it, and older
ones resolve to the newest version available to them.
`click.edit()` is not used anywhere in this package, so there is no
exploitable path here; this is supply-chain hygiene and unblocks the
downstream remediation.
Verified on Python 3.9.6:
- `pip install -e .` no longer downgrades click (stays at 8.1.8)
- full test suite: 25 passed, 5 skipped -- identical to the click 7.1.2 baseline
- `opensearchsql --help` and the doctest driver imports still work
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@dai-chen

Copy link
Copy Markdown
Collaborator

Shall we merge the commit SHA fix and get CI pass?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@RyanL1997@dai-chen@Swiddis
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Unpin click to remediate CVE-2026-7246 - #78

Open
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection
Open

Unpin click to remediate CVE-2026-7246#78
RyanL1997 wants to merge 2 commits into
opensearch-project:1.0-legacyfrom
RyanL1997:fix/cve-2026-7246-click-edit-injection

Conversation

@RyanL1997

Copy link
Copy Markdown

Description

Replaces the exact click == 7.1.2 pin in setup.py with a version requirement that admits the CVE-2026-7246 fix.

CVE-2026-7246 (High, CVSS 7.2) is a command injection in click.edit(), affecting click <= 8.3.2 and fixed in 8.3.3.

Two things are wrong with the current pin:

  1. It installs a vulnerable click.
  2. Because it is an exact pin, it also forces the vulnerable version back into any environment that installs this package next to a patched click.

Point 2 is the one that reaches beyond this repo. opensearch-project/sql's doctest bootstrap clones this branch and installs it right after its own requirements:

$DIR/.venv/bin/pip install -r $DIR/requirements.txt # click 8.x$DIR/.venv/bin/pip install -e ./sql-cli # <-- drags click back to 7.1.2

So the pending remediation there (opensearch-project/sql#5471) cannot actually take effect until this branch is unpinned.

Why environment markers instead of click >= 8.3.3

The patched release is only published for Python >= 3.10 (every click >= 8.2 sets Requires-Python >= 3.10), while this branch still supports Python 3.9. Requiring 8.3.3 unconditionally makes the package uninstallable on 3.9:

ERROR: Ignored the following versions that require a different python version: ... 8.3.3 Requires-Python >=3.10
ERROR: No matching distribution found for click==8.3.3

So the requirement is split by marker — interpreters that can take the fix are required to, and 3.9 resolves to the newest release available to it:

'click >= 8.3.3; python_version >= "3.10"',
'click >= 8.1.8, < 8.2; python_version < "3.10"',

Worth stating plainly: on Python 3.9 this lands on click 8.1.8, which is still inside the CVE's affected range, because upstream never backported the fix to a 3.9-compatible release. There is no version constraint that fixes 3.9 — that requires either moving off Python 3.9 or dropping the click dependency. This change fixes every interpreter that can be fixed and, more importantly, stops this package from downgrading click for consumers that are already on 3.10+.

Exploitability here

click.edit() is not called anywhere in this package (the click surface used is command/option/argument/echo/secho/confirm/echo_via_pager/Path/STRING/INT). This is supply-chain hygiene and a downstream unblock, not a live vulnerability in the CLI.

Issues Resolved

Unblocks opensearch-project/sql#5445 and opensearch-project/sql#5471.

Note that #5471 needs a companion change: it currently pins click==8.3.3 flat in doctest/requirements.txt, which fails to resolve on the Linux CI image (Python 3.9) and aborts the whole install, taking zc.customdoctests with it — that is the actual cause of its red build-linux (…, doc) checks, and it needs the same marker treatment (or a CI Python bump).

Testing

Verified locally on Python 3.9.6 (same minor version as the sql Linux doctest image):

  • Downgrade is gone — with click 8.1.8 already present, pip install -e . previously reinstalled 7.1.2; it now leaves 8.1.8 in place.
  • Test suitepytest tests/25 passed, 5 skipped, identical to the click 7.1.2 baseline (no new failures, same skips).
  • CLI smoke testopensearchsql --help renders correctly under click 8.
  • Downstream imports — the symbols sql's doctest/test_docs.py imports (Formatter, OpenSearchConnection, OutputSettings) all import cleanly under click 8.
  • Marker resolution — evaluated via packaging.requirements: 3.9 selects click<8.2,>=8.1.8; 3.10 and 3.12 select click>=8.3.3.

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

sql-cli 1.0-legacy pinned `click == 7.1.2` exactly. That pin is vulnerable
to CVE-2026-7246 (command injection in `click.edit()`), and because it is an
exact pin it also forces the vulnerable version back into any environment
that installs this package alongside a patched click.
This is what blocks opensearch-project/sql#5471: the doctest bootstrap runs
`pip install -r requirements.txt` followed by `pip install -e ./sql-cli`, so
sql-cli's pin downgrades click again in the second step.
The fix (click 8.3.3) is only published for Python >= 3.10, while this branch
still supports Python 3.9, so the requirement is expressed with environment
markers: interpreters that can take the patched release require it, and older
ones resolve to the newest version available to them.
`click.edit()` is not used anywhere in this package, so there is no
exploitable path here; this is supply-chain hygiene and unblocks the
downstream remediation.
Verified on Python 3.9.6:
- `pip install -e .` no longer downgrades click (stays at 8.1.8)
- full test suite: 25 passed, 5 skipped -- identical to the click 7.1.2 baseline
- `opensearchsql --help` and the doctest driver imports still work
Signed-off-by: Jialiang Liang <jiallian@amazon.com>
@dai-chen

Copy link
Copy Markdown
Collaborator

Shall we merge the commit SHA fix and get CI pass?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@RyanL1997@dai-chen@Swiddis