{"id":"CVE-2021-22557","aliases":["GHSA-j28r-j54m-gpc4","PYSEC-2021-429"],"url":"https://o3.security/vulnerability/CVE-2021-22557","summary":"Code Injection in SLO Generator","details":"SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator. We recommend upgrading SLO Generator past https://github.com/google/slo-generator/pull/173","published":"2021-10-04T10:15:07.197Z","modified":"2026-07-09T00:05:46.715530Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"PyPI","name":"slo-generator","fixedVersion":"2.0.1"}],"fix":{"url":"https://github.com/google/slo-generator/pull/173","label":"google/slo-generator#173"},"references":[{"type":"FIX","url":"https://github.com/google/slo-generator/pull/173"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/164426/Google-SLO-Generator-2.0.0-Code-Execution.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:05:46.715530Z"}}