xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE). User input is not properly checked to be numerical values prior to being evaluated.
{
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2023-07-11T22:46:05Z",
"nvd_published_at": "2023-07-11T15:15:20Z",
"severity": "CRITICAL"
}