CVE-2017-2810
HIGHTablib 0.11.4 - Command Injection
Title source: llmDescription
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.
Scores
CVSS v3
7.5
EPSS
0.0244
EPSS Percentile
84.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
Status
draft
Affected Products (2)
python/tablib
pypi/tablib
< 0.11.5PyPI
Timeline
Published
Jun 14, 2017
Tracked Since
Feb 18, 2026