id: PYSEC-2018-82 details: There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution. affected: - package: name: definitions ecosystem: PyPI purl: pkg:pypi/definitions ranges: - type: ECOSYSTEM events: - introduced: '0' versions: - 0.1.0 - 0.1.1 - 0.2.0 references: - type: REPORT url: https://github.com/danijar/definitions/issues/14 - type: ADVISORY url: https://github.com/advisories/GHSA-v4x4-98cg-wr4g aliases: - CVE-2018-20325 - GHSA-v4x4-98cg-wr4g modified: '2021-08-27T03:21:57.237018Z' published: '2018-12-21T23:29:00Z'