Loading vulnerability details...
An out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected.
Pillow 12.1.1 will be released shortly with a fix for this.
Image.open() has a formats parameter that can be used to prevent PSD images from being opened.
Pillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html
An out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected.
Pillow 12.1.1 will be released shortly with a fix for this.
Image.open() has a formats parameter that can be used to prevent PSD images from being opened.
Pillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html
This high-severity vulnerability could allow attackers to gain unauthorized access, execute arbitrary code, or compromise data integrity. Prompt remediation is strongly recommended.
Probability of exploitation in the next 30 days · more likely than 40.2% of all CVEs.
Apply security patches to version 12.1.1 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior