VYPR
Medium severity4.5NVD Advisory· Published Jul 6, 2026· Updated Jul 7, 2026

CVE-2026-55798

CVE-2026-55798

Description

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
PillowPyPI
< 12.3.012.3.0

Affected products

19

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.