A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration)
I am sure they are paid well but they literally have RCE embedded in their infra. How is this acceptable?