added note about security hole in execute function