pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
{ "cpes": [ "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*" ], "severity": "Low" }
"https://github.com/bitnami/vulndb/tree/main/data/python-min/BIT-python-min-2026-3479.json"