Filtered by vendor Mlalchemy Project
                         Subscriptions
                    
                    
                
                        Filtered by product Mlalchemy
                         Subscriptions
                    
                    
                
                    Total
                    1 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2017-16615 | 1 Mlalchemy Project | 1 Mlalchemy | 2025-04-20 | N/A | 
| An exploitable vulnerability exists in the YAML parsing functionality in the parse_yaml_query method in parser.py in MLAlchemy before 0.2.2. When processing YAML-Based queries for data, a YAML parser can execute arbitrary Python commands resulting in command execution because load is used where safe_load should have been used. An attacker can insert Python into loaded YAML to trigger this vulnerability. | ||||
                            
                                
                                
                                    Page 1 of 1.