—
PYSEC-2017-79
Details
An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML parser can execute arbitrary Python commands resulting in command execution. An attacker can insert Python into loaded YAML to trigger this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/django-make-app
Introduced in:
0.1.0.1No fixed version published yet for django-make-app (pip). Pin to a known-safe version or switch to an alternative.