CVE Explorer
CVE-2026-31900
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A malicious pull request could edit pyproject.toml to use a direct URL reference to a malicious repository. This could lead to arbitrary code execution in the context of the GitHub Action. Attackers could then gain access to secrets or permissions available in the con
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"black","vendor":"psf","versions":[{"status":"affected","version":"< 26.3.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cc526c4e2d9bc21e7a94954ce6dfbf0d28112aa45ddf88dcb28bffbc4d8099a6 · sha256:53ae27d99381b74c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cc526c4e2d9bc21e7a94954ce6dfbf0d28112aa45ddf88dcb28bffbc4d8099a6 · sha256:53ae27d99381b74c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc526c4e2d9bc21e7a94954ce6dfbf0d28112aa45ddf88dcb28bffbc4d8099a6 · sha256:53ae27d99381b74c… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/psf/black/commit/0a2560b981364dde4c8cf8ce9d164c40669a8611","tags":["x_refsource_MISC"],"url":"https://github.com/psf/black/commit/0a2560b981364dde4c8cf8ce9d164c40669a8611"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc526c4e2d9bc21e7a94954ce6dfbf0d28112aa45ddf88dcb28bffbc4d8099a6 · sha256:53ae27d99381b74c… · /containers/cna/references/1
{"name":"https://github.com/psf/black/security/advisories/GHSA-v53h-f6m7-xcgm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/psf/black/security/advisories/GHSA-v53h-f6m7-xcgm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc526c4e2d9bc21e7a94954ce6dfbf0d28112aa45ddf88dcb28bffbc4d8099a6 · sha256:53ae27d99381b74c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.