An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.
https://github.com/irmen/Pyro3/blob/master/docs/9-security.html#L341-L346
https://github.com/irmen/Pyro3/blob/master/Pyro/protocol.py#L672-L711
https://github.com/Sif-0x01/security-advisories/security/advisories/GHSA-7625-w9h5-83rv