An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collectyaml method in configobj.py. It can execute arbitrary Python commands, resulting in command execution.
"https://github.com/pypa/advisory-database/blob/main/vulns/donfig/PYSEC-2019-21.yaml"