fig. 01 — GHSA-c8m9-mh38-97p9, the advisory selected below
// advisories
GHSA-c8m9-mh38-97p9
HIGH
An XML eXternal Entity (XXE) Injection was discovered in pmml-model before version 1.4.3. A remote attacker can exploit this vulnerability by sending a request to submit malicious External Entity references within the embedded XML metadata to the target system.