{"schema_version":"1.7.5","id":"GHSA-rprw-h62v-c2w7","published":"2019-01-04T17:45:26Z","modified":"2026-07-01T17:45:34.796248930Z","aliases":["CVE-2017-18342","PYSEC-2018-49"],"summary":"PyYAML insecurely deserializes YAML strings leading to arbitrary code execution","details":"In PyYAML before 5.1, the `yaml.load()` API could execute arbitrary code. In other words, `yaml.safe_load` is not used.\n\nThis was intended to be fixed in 4.1, but due to [breaking changes](https://github.com/yaml/pyyaml/issues/192#issuecomment-401491470), 4.1 was yanked and 5.1 [contains](https://github.com/yaml/pyyaml/issues/207#issuecomment-472520007) the patch for CVE-2017-18342.","affected":[{"package":{"name":"pyyaml","ecosystem":"PyPI","purl":"pkg:pypi/pyyaml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1"}]}],"versions":["3.01","3.02","3.03","3.04","3.05","3.06","3.07","3.08","3.09","3.10","3.11","3.12","3.13","3.13b1","3.13rc1","4.2b1","4.2b2","4.2b4","5.1b1","5.1b3","5.1b5","5.1b7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-rprw-h62v-c2w7/GHSA-rprw-h62v-c2w7.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-18342"},{"type":"WEB","url":"https://github.com/marshmallow-code/apispec/issues/278"},{"type":"WEB","url":"https://github.com/yaml/pyyaml/issues/193"},{"type":"WEB","url":"https://github.com/yaml/pyyaml/issues/207#issuecomment-472520007"},{"type":"WEB","url":"https://github.com/yaml/pyyaml/pull/74"},{"type":"WEB","url":"https://github.com/yaml/pyyaml/commit/7b68405c81db889f83c32846462b238ccae5be80"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2018-49.yaml"},{"type":"PACKAGE","url":"https://github.com/yaml/pyyaml"},{"type":"WEB","url":"https://github.com/yaml/pyyaml/blob/master/CHANGES"},{"type":"WEB","url":"https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEX7IPV5P2QJITAMA5Z63GQCZA5I6NVZ"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSQQMRUQSXBSUXLCRD3TSZYQ7SEZRKCE"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M6JCFGEIEOFMWWIXGHSELMKQDD4CV2BA"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202003-45"}],"database_specific":{"cwe_ids":["CWE-502"],"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:55:26Z","nvd_published_at":null,"severity":"CRITICAL"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}