Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
{ "urgency": "not yet assigned" }