An exploitable vulnerability exists in the YAML parsing functionality in the readyamlfile method in ioutils.py in djangomake_app 0.1.3. A YAML parser can execute arbitrary Python commands resulting in command execution. An attacker can insert Python into loaded YAML to trigger this vulnerability.
{
"extracted_events": [
{
"introduced": "0.1.3"
},
{
"last_affected": "0.1.3"
}
],
"source": "CPE_STRING",
"cpe": "cpe:2.3:a:django_make_app_project:django_make_app:0.1.3:*:*:*:*:*:*:*"
}