Medium severity4.5NVD Advisory· Published Jul 6, 2026· Updated Jul 7, 2026
CVE-2026-55798
CVE-2026-55798
Description
Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PillowPyPI | < 12.3.0 | 12.3.0 |
Affected products
19- osv-coords17 versionspkg:apk/chainguard/superset-6.0pkg:apk/chainguard/mlflowpkg:apk/chainguard/superset-6.1pkg:apk/chainguard/tensorflow-gpu-jupyterpkg:apk/chainguard/label-studiopkg:apk/chainguard/lmcache-cuda-12.8pkg:apk/chainguard/openstack-horizon-2025.2pkg:apk/chainguard/text-generation-inferencepkg:apk/chainguard/openstack-horizon-2025.2-fipspkg:bitnami/pillowpkg:apk/chainguard/openstack-horizon-2026.1pkg:apk/chainguard/openstack-horizon-2026.1-fipspkg:apk/chainguard/superset-fips-6.1pkg:apk/chainguard/tritonserver-backend-vllm-cuda-13.0pkg:apk/wolfi/mlflowpkg:apk/wolfi/superset-6.0pkg:apk/wolfi/superset-6.1
< 6.0.0-r13+ 16 more
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: < 2.21.0-r7
- (no CPE)range: < 1.23.0-r11
- (no CPE)range: < 0.5.3-r0
- (no CPE)range: < 25.5.2_git20260617-r4
- (no CPE)range: < 3.3.7-r20
- (no CPE)range: < 25.5.2_git20260617-r5
- (no CPE)range: < 12.3.0
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 6.1.0-r5
- (no CPE)range: < 25.11-r11
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 6.1.0-r6
<12.3.0+ 1 more
- (no CPE)range: <12.3.0
- cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*range: <12.3.0
Patches
Vulnerability mechanics
References
8- github.com/python-pillow/Pillow/commit/8404ea5fe5df40fc34aa1e51403dd6fce0778b8anvdPatchWEB
- github.com/python-pillow/Pillow/commit/88194166691b7b603529b8b036ab3ab9cedd2de4nvdPatchWEB
- github.com/python-pillow/Pillow/commit/b0e06caa64c1405aa3da0bb1d2bd9a77ca22de7fnvdPatchWEB
- github.com/python-pillow/Pillow/security/advisories/GHSA-4x4j-2g7c-83w6nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-4x4j-2g7c-83w6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55798ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2257.yamlghsaWEB
- github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rstnvdRelease NotesWEB
News mentions
0No linked articles in our index yet.