Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-w9cp-3x79-2p8p: transmute-core unsafe YAML deserialization vulnerability

Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.

ghsa
#vulnerability#git

transmute-core unsafe YAML deserialization vulnerability

Moderate severity GitHub Reviewed Published Nov 2, 2023 to the GitHub Advisory Database • Updated Nov 2, 2023

Related news

CVE-2023-47204: fix(yaml_serializer): use yaml.SafeLoader by toumorokoshi · Pull Request #58 · toumorokoshi/transmute-core

Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.