VDB
Sign up
—

PYSEC-2017-79

Details

An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML parser can execute arbitrary Python commands resulting in command execution. An attacker can insert Python into loaded YAML to trigger this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django-make-app
Introduced in: 0.1.0.1

No fixed version published yet for django-make-app (pip). Pin to a known-safe version or switch to an alternative.

References