An error in separating the path and filename of the CGI script to run in http.server.CGIHTTPRequestHandler allows running arbitrary executables in the directory under which the server was started.
http.server.CGIHTTPRequestHandler
{ "cwe_ids": [] }
"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2013-3.json"