CVE-2023-50447General(debian / debian_linux)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-95

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • pillow

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
debian_linuxpillow

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-19: 1Mentions · 2026-04-11: 1Technical Details · 2026-02-19: 102-1904-11
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-191
General1
2026-04-111
Disclosure1
Full discourse2 posts
  • Veros@boldnames
    Disclosure

    Don't just take my word for it, verify. We scanned a trending public Github repository by @Microsoft at microsoft/markitdown and found 2 critical OSVs interlinked to 6 CVEs, among other findings: https://github.com/microsoft/markitdown Dependencies: Pillow>=9.0.0 -> CVE-2023-50447, CVE-2024-28219, CVE-2023-44271. mcp~=1.8.0 -> CVE-2025-53366, CVE-2025-66416, CVE-2025-53365. Per this post, the dependency still exist at > >markitdown-ocr/pyproject.toml >markitdown-mcp/pyproject.toml

    Post summary

    The tweet reports discovery of six critical CVEs linked to a Microsoft public GitHub repository, presenting the CVE IDs but providing no exploitation details or remediation information.

    10100263
    4.6K followersView on X
  • Ayush Rijith@AyushRijith
    General

    @_ar9av @prismor_dev the critical ones include CVE-2025-29927 , CVE-2025-7783 , CVE-2023-50447 , CVE-2025-43859, CVE-2023-39662 , CVE-2024-23751 , CVE-2025-1793 this one has a sql injection vulnerability , CVE-2023-39631 , CVE-2024-3829 , CVE-2023-6730 , CVE-2025-64712 and more..

    Post summary

    The tweet lists several critical CVEs and notes that CVE-2025-1793 involves SQL injection, but it lacks PoCs, exploitation tools, or patch information, making it a general notice of vulnerabilities.

    0002079
    6 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
Apppythonpillow---

Explore more