A vulnerability chain called AutoJack in Microsoft's AutoGen Studio could let attackers execute arbitrary commands on a host system via a malicious webpage. The issue was remediated before any PyPI release, so only developers building from GitHub during a limited window were exposed.
Tap to vote and see what everyone thinks.
Summary by ByteBrief