Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| babel(PyPI) | 0 | 2.9.1 | N/A |
CVSS Metrics