CVE Feed

    Dashboard / CVE / CVE-2026-31900

    CVE-2026-31900

    Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A malicious pull request could edit pyproject.toml to use a direct URL reference to a malicious repository. This could lead to arbitrary code execution in the context of the GitHub Action. Attackers could then gain access to secrets or permissions available in the context of the action. Version 26.3.0 fixes this vulnerability.

    Published:Mar 11, 2026
    Last Modified:Mar 20, 2026
    EPS:Mar 11, 2026
    EPSS Score:0.00184
    CVSS Score:9.8

    Affected Products

    Vendor
    Psf
    Product
    Black
    Vendor
    Python
    Product
    Black

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High