Junglewise Threat Intelligence

CVE-2026-32274: psf Black arbitrary file write via unsanitized cache filename

CVE-2026-32274 · Severity: high · CVSS 7.5 · Published 2026-03-12

Technologies: Red Hat OpenShift Lightspeed, black (PyPI). Vendors: Red Hat, PyPI.

Executive brief

Black, a popular Python code formatter, contains a vulnerability that allows an attacker to write files to unauthorized locations on a computer's file system. By providing a specially crafted input to a specific configuration option, an attacker could potentially overwrite critical system or application files. This could lead to system instability or be used as a stepping stone for further attacks.

Technical details

A path traversal vulnerability exists in Black's caching mechanism. The application constructs cache filenames using various formatting options, including the value provided to the `--python-cell-magics` command-line argument. Because this value is not sanitized before being incorporated into the file path, an attacker who can control this argument can perform a path traversal attack to write cache files to arbitrary locations on the filesystem. This is tracked as CWE-22. The issue is fixed in version 26.3.1 by implementing proper sanitization of the affected option.

Affected products

  • psf black >= 24.3.0, < 26.3.1

Timeline

  • 2026-03-12: disclosed
  • 2026-03-12: advisory
  • 2026-03-12: patched

References

Related threats