Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-38169.json"