Safety vulnerability ID: 43004
The information on this page was manually curated by our Cybersecurity Intelligence Team.
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 9.14.1
LaunchDarkly SDK for Python
[This affected versions has been limited. Please create a free account to view the full affected versions.]
[This fixed versions has been limited. Please create a free account to view the full fixed versions.]
Fixed:
- Changed `Files.new_data_source()` to use `yaml.safe_load()` instead of `yaml.load()` for YAML/JSON test data parsing. This disables `pyyaml` extended syntax features that could allow arbitrary code execution. ([136](https://github.com/launchdarkly/python-server-sdk/issues/136))
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application