The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.11.2-1", "binary_name": "python-tqdm" }, { "binary_version": "4.11.2-1", "binary_name": "python3-tqdm" } ] }