GHSA-2MHW-8QCG-GR96: GHSA-2mhw-8qcg-gr96: Supply Chain RCE in skia-python via Vendored libfreetype (CVE-2025-27363)
GHSA-2mhw-8qcg-gr96: Supply Chain RCE in skia-python via Vendored libfreetype (CVE-2025-27363)
Vulnerability ID: GHSA-2MHW-8QCG-GR96
CVSS Score: 8.1
Published: 2026-03-19
The skia-python package implicitly vendors a vulnerable version of libfreetyp...
cvereports.hashnode.dev2 min read