VDB
KO
MEDIUM 4.5

PYSEC-2026-2257

Quick fix

PYSEC-2026-2257 — pillow: upgrade to the fixed version with the command below.

pip install --upgrade 'pillow>=12.3.0'

Details

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 12.3.0
Fix pip install --upgrade 'pillow>=12.3.0'

References