A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
https://www.suse.com/de-de/security/cve/CVE-2017-9274/
https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00024.html