psd-tools
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting psd-toolspage 1 of 1
- CVE-2020-10571CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.42020-03-14
vulnerable: 0.1.1 ... 1.9.3 (57 versions)
An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious data.
- CVE-2026-27809CRITICALCVSS 9.1EG 9.1✓ Fixed in 1.12.22026-02-26
vulnerable: 0.1.1 ... 1.9.9 (105 versions)
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() rais…
- CVE-2026-49836MEDIUMCVSS 4.6EG 4.6✓ Fixed in 1.17.12026-07-09
vulnerable: 0.1.1 ... 1.9.9 (115 versions)
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled an…
Check whether psd-tools is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for psd-tools CVEs against the assets you own.
Start Free Scan →