python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.
"https://github.com/pypa/advisory-database/blob/main/vulns/python-docx/PYSEC-2016-21.yaml"