Version 5.3.2 of the Astropy core package is vulnerable to remote code
execution due to improper input validation in the
TranformGraph().to_dot_graph
function. A malicious user can provide a
command or a script file as a value to the savelayout
argument, which
will be placed as the first value in a list of arguments passed to
subprocess.Popen
. Although an error will be raised, the command or
script will be executed successfully. (CVE-2023-41334)