{"id":"PYSEC-2021-380","details":"Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the checkout_repo function is called on a maliciously crafted file. An attacker can leverage this to execute arbitrary code on the victim machine.","aliases":["CVE-2021-40720","GHSA-x23q-4j9j-9cxw"],"modified":"2026-06-10T17:02:27.548173342Z","published":"2021-10-15T15:15:00Z","references":[{"type":"WEB","url":"https://helpx.adobe.com/security/products/ops_cli/apsb21-88.html"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-x23q-4j9j-9cxw"}],"affected":[{"package":{"name":"ops-cli","ecosystem":"PyPI","purl":"pkg:pypi/ops-cli"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.5"}]}],"versions":["1.10.0","1.10.1","1.11.0","1.11.1","1.11.10","1.11.11","1.11.12","1.11.2","1.11.3","1.11.4","1.11.5","1.11.6","1.11.7","1.11.8","1.11.9","1.12.1","1.12.2","2.0.3","2.0.4"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/ops-cli/PYSEC-2021-380.yaml"}}],"schema_version":"1.7.5"}