Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-55798

Опубликовано: 06 июл. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 4.5

Описание

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

РелизСтатусПримечание
devel

not-affected

12.3.0-1ubuntu1
esm-infra-legacy/trusty

not-affected

windows only
esm-infra-legacy/xenial

not-affected

windows only
esm-infra/bionic

not-affected

windows only
esm-infra/focal

not-affected

windows only
jammy

not-affected

windows only
noble

not-affected

windows only
resolute

not-affected

windows only
upstream

released

12.3.0-1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

windows only
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
redhat
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

CVSS3: 4.5
nvd
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

CVSS3: 4.5
debian
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get ...

CVSS3: 4.5
github
2 месяца назад

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

4.5 Medium

CVSS3