Advisories for Pypi/Lookatme package

2020

OS Command Injection

In lookatme, the package automatically loaded the built-in terminal and file_loader extensions. As a workaround, the lookatme/contrib/terminal.py and lookatme/contrib/file_loader.py files may be manually deleted. Additionally, it is always recommended to be aware of what is being rendered with lookatme.