Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
"https://github.com/pypa/advisory-database/blob/main/vulns/babel/PYSEC-2021-421.yaml"