init.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.
"https://github.com/pypa/advisory-database/blob/main/vulns/numpy/PYSEC-2018-33.yaml"