OS Command Injection in Pillow - CVE-2026-55798
Published: July 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to command injection in WindowsViewer.get_command() in src/PIL/ImageShow.py when processing a file path in a shell command. A remote attacker can supply a specially crafted file path containing shell metacharacters to execute arbitrary commands.
User interaction is required to open a crafted file path on a Windows system.
Affected software
Fedora
python-pillow
How to mitigate CVE-2026-55798
python-pillow - addressed in versions 11.3.0-9.fc43, 11.3.0-10.fc43, 12.3.0-1.fc44