🧬 Known OSS vulnerabilities — OSV-Scannerⓘ2 found · 2 serious
Your dependencies cross-checked against the OSV vulnerability database.
SeriousPYSEC-2018-49 In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced fo
A package you depend on has a known security hole (CVE-2017-18342). Fix: Update that package to its patched version.
SeriousPYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or
About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.