Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55798

Опубликовано: 06 июл. 2026
Источник: nvd
CVSS3: 4.5
EPSS Низкий

Описание

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Версия до 12.3.0 (исключая)

EPSS

Процентиль: 7%
0.00177
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 4.5
ubuntu
29 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

CVSS3: 4.5
redhat
29 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

CVSS3: 4.5
debian
29 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get ...

CVSS3: 4.5
github
15 дней назад

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

EPSS

Процентиль: 7%
0.00177
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-78