GHSA-fr75-x856-q6j8, CVE-2021-36711
pypi/OctoBot
Unrestricted Upload of File with Dangerous Type
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
All versions before 0.4.4
Upgrade to version 0.4.4 or above.
2022-07-26
source |