MEDIUM
psd-tools
CVE published 2026-09-10
CVE-2026-49836
CVE-2026-49836 debrief: The psd-tools package has a vulnerability that allows path traversal and arbitrary file read. Prior to version 1.17.1, the `SmartObject.save()` method writes an embedded smart object to a path taken verbatim from the PSD file, allowing an attacker to write to an arbitrary location. This could lead to potential code execution and data exfiltration. Defenders should assess exposure a [truncated]