pypi package report

Is pygments safe?

5 known vulnerabilities, worst severity CRITICAL.

// reach

1 direct dependencies

none carry a known advisory

    288 packages depend on it

    an advisory here reaches each of them

    Create a free accountfor every dependency path, dependent and what to upgrade
    // ai model usage

    No published models are known to use this package.


    cvss
    0.0
    critical

    severity band, no base score published

    epss
    0.00%
    high

    chance of exploitation in 30 days, 94th percentile of all CVEs

    xyz score
    not scored

    CyberXYZ composite out of 10

    fig. 01 — GHSA-fff8-4w9p-7v76, the advisory selected below

    // 5 advisories

    GHSA-fff8-4w9p-7v76

    CRITICALCVE-2015-8557

    The FontManager.getnixfontpath function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

    // cvss v3.0 vector

    CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

    Attack vector
    Network
    Attack complexity
    High
    Privileges required
    None
    User interaction
    None
    Scope
    Changed
    Confidentiality
    High
    Integrity
    High
    Availability
    High

    Checked 2026-09-23 at 02:25 UTC. The most recent advisory here was published 2026-03-22. Updated continuously from NVD, GHSA, OSV and CNA feeds.

    Think a verdict here is wrong? Tell us — we respond within 2 business days.
    Is pygments safe? pypi package security report | CyberXYZ