# Vulnerability in `pygmalion`, `pygmalion-virtualenv`...
Critical severity
Unreviewed
Published
Dec 1, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Nov 30, 2021
Published to the GitHub Advisory Database
Dec 1, 2021
Last updated
Feb 1, 2023
Vulnerability in
pygmalion
,pygmalion-virtualenv
andrefined
themes Description: these themes useprint -P
on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be exploited. Fixed in: b3ba9978. Impacted areas: -pygmalion
theme. -pygmalion-virtualenv
theme. -refined
theme.References