Understanding Python Pickle Insecurity

前端 未结 4 1288
谎友^
谎友^ 2021-01-05 10:37

It states in the Python documentation that pickle is not secure and shouldn\'t parse untrusted user input. If you research this; almost all examples demonstrat

4条回答
  •  悲&欢浪女
    2021-01-05 11:00

    For altogether too much information on writing malicious Pickles that go much further than the standard os.system() example, see this presentation and its accompanying paper.

提交回复
热议问题