The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.
"https://github.com/pypa/advisory-database/blob/main/vulns/embedchain/PYSEC-2024-7.yaml"