base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.
"https://github.com/pypa/advisory-database/blob/main/vulns/rope/PYSEC-2018-100.yaml"