—
PYSEC-2023-223
Quick fix
PYSEC-2023-223 — transmute-core: upgrade to the fixed version with the command below.
pip install --upgrade 'transmute-core>=1.13.5'Details
Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/transmute-core
Introduced in:
0Fixed in: 1.13.5Fix
pip install --upgrade 'transmute-core>=1.13.5'