pinterest-api-sdk is vulnerable to Deserialization of Untrusted Data
70
High Risk
Affected versions of this package are vulnerable to Arbitrary Code Execution via Unsafe YAML Deserialization because they use the yaml.load() API to process untrusted YAML input. An attacker can exploit this by providing a maliciously crafted YAML file that contains embedded Python commands, which are then automatically executed during the deserialization process, potentially leading to a complete system compromise.
You are affected if you are using a version that falls within the vulnerable range.
pinterest-api-sdk is vulnerable to Deserialization of Untrusted Data in versions 0.2.0 - 0.2.5.
Upgrade the pinterest-api-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant