mirror of
https://github.com/OpenBB-finance/OpenBB.git
synced 2026-05-22 22:41:07 +08:00
eval() on unsanitized CLI input allowed arbitrary code execution via crafted --key payloads. ast.literal_eval is a safe drop-in that only parses Python literals and raises ValueError/SyntaxError on expressions. Also narrows the except clause and fixes the fallback key stripping bug. Co-authored-by: Danglewood <85772166+deeleeramone@users.noreply.github.com>