Loading vulnerability details...
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
This critical vulnerability poses an immediate and severe threat to system security. Exploitation could lead to complete system compromise, data breach, or denial of service. Immediate action is required.
Probability of exploitation in the next 30 days · more likely than 88.3% of all CVEs.
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior