VDB
KO

PYSEC-2022-10

Details

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 9.0.0
Fix pip install --upgrade 'pillow>=9.0.0'

References