Sqlayamlfixtures 0.9.1 allows local users to execute arbitrary python code via the fixturetext argument in sqlayaml_fixtures.load.
"https://github.com/pypa/advisory-database/blob/main/vulns/sqla-yaml-fixtures/PYSEC-2019-122.yaml"