PatchSiren

psd-tools CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM psd-tools CVE published 2026-09-10

CVE-2026-49836

CVE-2026-49836 debrief: The psd-tools package has a vulnerability that allows path traversal and arbitrary file read. Prior to version 1.17.1, the `SmartObject.save()` method writes an embedded smart object to a path taken verbatim from the PSD file, allowing an attacker to write to an arbitrary location. This could lead to potential code execution and data exfiltration. Defenders should assess exposure a [truncated]