Safety vulnerability ID: 41397
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Trackthenews 0.1.10 includes a security patch for the function 'main' in 'trackthenews/core.py'. It used the unsafe yaml.load(), that allows instantiation of arbitrary objects. Consider yaml.safe_load().
https://github.com/freedomofpress/trackthenews/commit/7ef1ae9d3ac2793e55d9df4161eddb46ff9a9fde
Latest version: 0.4
Monitor RSS feeds for keywords and act on matching results. A special project of the Freedom of the Press Foundation.
Trackthenews version 0.1.10 includes a security patch for the function 'main' in 'trackthenews/core.py'. Use of unsafe yaml load. Allows instantiation of arbitrary objects. Consider yaml.safe_load(). See also: https://github.com/freedomofpress/trackthenews/commit/7ef1ae9d3ac2793e55d9df4161eddb46ff9a9fde
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application