CPE
The heym expression engine before version 0.0.91 is vulnerable to a sandbox escape via the DotList map/filter and fallback resolver, allowing authenticated users to achieve arbitrary Python code execution.