Headline
GHSA-w9cp-3x79-2p8p: transmute-core unsafe YAML deserialization vulnerability
Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.
transmute-core unsafe YAML deserialization vulnerability
Moderate severity GitHub Reviewed Published Nov 2, 2023 to the GitHub Advisory Database • Updated Nov 2, 2023
Related news
CVE-2023-47204: fix(yaml_serializer): use yaml.SafeLoader by toumorokoshi · Pull Request #58 · toumorokoshi/transmute-core
Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.