CVE-2014-3007: Python Pillow
High severity, CVSS 10.0. EPSS: 10.4% chance of exploitation in the next 30 days.
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.
Affected products
- Python Pillow: version 2.3.0 only
- Pythonware Python Imaging Library: up to and including 1.1.7
Published 2014-04-27. Last modified 2026-06-17.