CVE-2019-3575: Sqla Yaml Fixtures Project Sqla Yaml Fixtures
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
Affected products
- Sqla Yaml Fixtures Project Sqla Yaml Fixtures: version 0.9.1 only
Published 2019-01-03. Last modified 2026-06-17.