← Back to browse · API

CVE-2022-22817

Severity
CRITICAL
CVSS
9.8
EPSS
0.03399
Risk score
40.39
CISA KEV
No
PoC
No
Published
2022-01-07
Modified
2024-10-15
First seen
2026-08-07
Aliases
EUVD-2022-0195, GHSA-8VJ2-VXX3-667W, PYSEC-2022-10
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-0195

Description

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.

References