VAITP Dataset

← Back to the dataset

CVE-2026-55798

Pillow's WindowsViewer allows shell injection via unescaped file paths.

  • CVSS 4.5
  • CWE-78
  • Input Validation and Sanitization
  • Local

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(…, shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.

CVSS base score
4.5
Published
2026-07-06
OWASP
A03 Injection
Orthogonal defect classification
Checking
Code defect classification
Missing Check
Category
Input Validation and Sanitization
Subcategory
Command Injection
Accessibility scope
Local
Impact
Arbitrary Code Execution
Affected component
Pillow
Fixed by upgrading
Yes

Solution

Upgrade Pillow to version 12.3.0 or later.

Vulnerable code sample

import subprocess

# This code is a representation of the vulnerable pattern described in the CVE.
# It is not the exact source code from the Pillow library but functionally
# demonstrates the same vulnerability.

class WindowsViewer:
    def get_command(self, file, **options):
        # The file path is embedded directly into the command string without escaping.
        command = f"start /WAIT {file}"
        return command

    def show_file(self, path):
        # The command containing the unescaped path is executed with shell=True.
        command = self.get_command(path)
        subprocess.Popen(command, shell=True)

Patched code sample

import subprocess

def get_command_and_args_secure(file_path: str):
    """
    Securely prepares a command and its arguments as a list.

    Instead of embedding the file path into a command string, this function
    constructs a list of arguments. The file path is treated as a single,
    distinct argument, preventing shell metacharacters within the path from
    being interpreted by a shell. This is the core principle of the fix.
    """
    # On Windows, Pillow's viewer uses 'mspaint.exe' to display images.
    # The command and its argument (the file path) are separate items in a list.
    return ["mspaint.exe", file_path]

def show_image_fixed(file_path: str):
    """
    Executes a command to show an image, preventing command injection.

    This function calls subprocess.Popen with a list of arguments and the
    default shell=False. The operating system handles the creation of the
    new process, ensuring that the file_path is passed as a single, literal
    argument to mspaint.exe, without any shell interpretation.
    """
    # Get the command and arguments as a safe list.
    args_list = get_command_and_args_secure(file_path)

    # Execute the command securely. No shell is used.
    subprocess.Popen(args_list)

Payload

`exploit.jpg" & calc.exe & "`

Cite this entry

@misc{vaitp:cve202655798,
  title        = {{Pillow's WindowsViewer allows shell injection via unescaped file paths.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-55798},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-55798/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::