GHSA-mwgj-7x7j-6966
GitHub Security Advisory
Deserialization of Untrusted Data in ParlAI
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.
Affected Packages
PyPI
parlai
Affected versions:
0
(fixed in 1.1.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 10, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.