4 ms·
Right, and then if you do literally anything with the output other than print() to a tty, it’s an escaping/injection attack. any_func(f"{attacker_provided}") <
by bcoates 1y ago
Right, and then if you do literally anything with the output other than print() to a tty, it’s an escaping/injection attack.
any_func(f"{attacker_provided}") <=> eval(attacker_provided), from a security/correctness perspective
- saagarjha 1y agoHow is this any different from any_func(attacker_provided)
- rowanG077 1y agoShooting any unsanitized input into your application is bad. template strings don't make this worse. any_func(attacker_provided) is even worse then any_func(t"{attacker_provided}") since in the later case you actually have reduced the attack surface to just strings.