Skip to content

[Aikido] Fix security issue in pillow via minor version upgrade from 12.1.0 to 12.1.1#21

Open
aikido-autofix[bot] wants to merge 1 commit intomainfrom
fix/aikido-security-update-packages-16215073-6J8J
Open

[Aikido] Fix security issue in pillow via minor version upgrade from 12.1.0 to 12.1.1#21
aikido-autofix[bot] wants to merge 1 commit intomainfrom
fix/aikido-security-update-packages-16215073-6J8J

Conversation

@aikido-autofix
Copy link

Upgrade Pillow to patch critical PSD image parsing vulnerability with potential out-of-bounds write and remote code execution risk

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-25990
HIGH
[pillow] Out-of-bounds write vulnerability in PSD image parsing allows potential remote code execution or system compromise when loading maliciously crafted image files with unexpected memory manipulation.
🔗 Related Tasks

@aikido-autofix aikido-autofix bot requested a review from a team as a code owner February 12, 2026 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants