{"id":"CVE-2017-16616","details":"An exploitable vulnerability exists in the YAML parsing functionality in the YAMLParser method in Interfaces.py in PyAnyAPI before 0.6.1. A YAML parser can execute arbitrary Python commands resulting in command execution because load is used where safe_load should have been used. An attacker can insert Python into loaded YAML to trigger this vulnerability.","aliases":["GHSA-vg8g-jpm9-jh8r","PYSEC-2017-23"],"modified":"2026-07-08T15:10:50.185410Z","published":"2017-11-08T03:29:00.247Z","references":[{"type":"WEB","url":"https://pypi.python.org/pypi/pyanyapi/0.6.1"},{"type":"ADVISORY","url":"https://github.com/Stranger6667/pyanyapi/releases/tag/0.6.1"},{"type":"ADVISORY","url":"https://joel-malwarebenchmark.github.io/blog/2017/11/08/cve-2017-16616-yamlparser-in-pyanyapi/"},{"type":"REPORT","url":"https://github.com/Stranger6667/pyanyapi/issues/41"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stranger6667/pyanyapi","events":[{"introduced":"0"},{"fixed":"90f862de7e2546dcf74cf2fdfabcc27b880ab98c"}],"database_specific":{"cpe":"cpe:2.3:a:pyanyapi_project:pyanyapi:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.6.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.5.7","0.5","0.4","v0.3","v0.2.1","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16616.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}