It was found that using yaml.load() API on untrusted input could lead to arbitrary code execution (CVE-2017-18342).
{ "section": "core" }