Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory
traversal, leading to code execution.
Babel version is fixed in django-hordak to 2.5.1, so I am unable to update to the newest version.
Dependabot shows me this warning:
Babel version is fixed in
django-hordak
to2.5.1
, so I am unable to update to the newest version.