modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
"https://github.com/pypa/advisory-database/blob/main/vulns/modulemd/PYSEC-2019-153.yaml"