Executive brief
Pillow, a popular Python library for image processing, contains a vulnerability in its Windows-specific image viewing component. If an application using Pillow is tricked into processing a file with a specially crafted name, an attacker could execute unauthorized commands on the underlying Windows system. This could lead to a full system compromise, data theft, or service disruption depending on the permissions of the application.
Technical details
The vulnerability is an OS command injection (CWE-78) located in `src/PIL/ImageShow.py` within the `WindowsViewer.get_command()` method. The root cause is the direct embedding of the `file` path parameter into an f-string used for a `cmd.exe` command without proper escaping or neutralization. This command is subsequently executed via `subprocess.Popen(..., shell=True)`. An attacker can use double-quotes to break out of the path string and use the `&` operator to append arbitrary commands. While macOS and Linux implementations use `shlex.quote()`, the Windows implementation lacks this protection. The vulnerability is exploitable if an attacker can control the filename passed to the viewer. A fix is available in version 12.3.0.
Affected products
- python-pillow Pillow < 12.3.0
Timeline
- 2026-07-03: disclosed: Vulnerability published to python-pillow/Pillow repository.
- 2026-07-06: advisory: NVD published CVE-2026-55798.
- 2026-07-20: advisory: GitHub Advisory GHSA-4x4j-2g7c-83w6 published.