Loading
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
Use Python vendor hub and Pillow product page to widen CVE-2022-22817 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-30595, CVE-2022-24303 and CVE-2026-40192 for nearby disclosures in the same product family.