Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the checkout_repo function is called on a maliciously crafted file. An attacker can leverage this to execute arbitrary code on the victim machine.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ops-cli(PyPI) | 0 | 2.0.5 | N/A |
CVSS Metrics