CVE-2017-16616

CRITICAL

PyAnyAPI <0.6.1 - Command Injection

Title source: llm
STIX 2.1

Description

An exploitable vulnerability exists in the YAML parsing functionality in the YAMLParser method in Interfaces.py in PyAnyAPI before 0.6.1. A YAML parser can execute arbitrary Python commands resulting in command execution because load is used where safe_load should have been used. An attacker can insert Python into loaded YAML to trigger this vulnerability.

References (4)

Core 4

Scores

CVSS v3 9.8
EPSS 0.0362
EPSS Percentile 88.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
pyanyapi_project/pyanyapi < 0.6.1
pypi/pyanyapi 0 - 0.6.1PyPI
Published Nov 08, 2017
Tracked Since Feb 18, 2026