Skip to content

yarrtist has a massive security vulnerability

https://gitlab.cern.ch/YARR/yarrtist/-/blob/f595bd5ab268fa2efddd617d358f72845e01898e/src/yarrtist/utils/utils.py#L78-84

There is never a scenario where you need to be recursively scanning an entire filesystem to find configs. This is really dangerous code.

./cc @theim