ymlref allows code injection.
"https://github.com/pypa/advisory-database/blob/main/vulns/ymlref/PYSEC-2018-103.yaml"