psd-tools vulnerabilities
CVEs whose affected-version data names the psd-tools package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-49836Medium· 4.6PoCpsd-tools: arbitrary file write via smart-object filename
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …
▾ Twilightpsd-tools · psd-toolsEPSS 0.16%via CVEORG
CVE-2026-27809Mediumpsd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
▾ Sunlitpsd-tools · psd-toolsEPSS 0.41%via OSV