CRITICAL 9.0 PyPI

Command Injection in Pygments

GHSA-fff8-4w9p-7v76 · CVE-2015-8557 · PYSEC-2016-32

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

Ready to move

Start Securing

Free, no credit card | First findings in minutes