VDB
KO

PYSEC-2022-168

Details

Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 9.0.1
Fix pip install --upgrade 'pillow>=9.0.1'

References