VYPR

lookatme

by d0c-s4vage

CVEs (1)

  • CVE-2020-15271Oct 26, 2020
    risk 0.00cvss epss 0.00

    In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system. This is…