Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
- https://duartecsantos.github.io/2023-01-02-CVE-2023-50447/
- https://duartecsantos.github.io/2024-01-02-CVE-2023-50447/
- https://github.com/NVIDIA-AI-Blueprints/vulnerability-analysis
- https://github.com/Swapnilalone901/vna
- https://github.com/katherineh123/temp-vuln-analysis