An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python commands, resulting in command execution.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| donfig(PyPI) | 0 | 0.4.0 | N/A |
CVSS Metrics