python-rply before 0.7.4 insecurely creates temporary files.
"https://github.com/pypa/advisory-database/blob/main/vulns/rply/PYSEC-2019-202.yaml"