3 ms·
Here's an article which explains in detail how pickles/serialization work in Python, and how pickles can be constructed to evaluate malicious code when they are
by foob 8y ago
Here's an article which explains in detail how pickles/serialization work in Python, and how pickles can be constructed to evaluate malicious code when they are deserialized. That's specifically about Python, but the same issue exists in many other languages.
[1] - https://intoli.com/blog/dangerous-pickles/ https://intoli.com/blog/dangerous-pickles/