imageio@1.5 vulnerabilities

Library for reading and writing a wide range of image, video, scientific, and volumetric data formats.

  • latest version

    2.37.0

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the imageio package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary Code Injection

    imageio is a Python library that provides an easy interface to read and write a wide range of image data, including animated images, volumetric data, and scientific formats.

    Affected versions of this package are vulnerable to Arbitrary Code Injection. An attacker can set the filename and inject code in the shell for Windows users that have dcmtk installed.

    Note: This vulnerability only affects Windows users.

    How to fix Arbitrary Code Injection?

    Upgrade imageio to version 2.6.0 or higher.

    [,2.6.0)