Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://github.com/toumorokoshi/transmute-core/releases/tag/v1.13.5 | release notes |
https://github.com/toumorokoshi/transmute-core/pull/58 | patch issue tracking |