An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2023-5.json"