An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33391.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "5.7.28" } ] } ]