greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the loadobj function at /templates/pickleutils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.
"https://github.com/pypa/advisory-database/blob/main/vulns/greykite/PYSEC-2024-276.yaml"