Skip to content

checker: detect insecure pickle deserialization with user tainted data#173

Merged
sourya-deepsource merged 1 commit intoDeepSourceCorp:masterfrom
MashyBasker:checker/django-insecure-pickle-deserialize
Mar 21, 2025
Merged

checker: detect insecure pickle deserialization with user tainted data#173
sourya-deepsource merged 1 commit intoDeepSourceCorp:masterfrom
MashyBasker:checker/django-insecure-pickle-deserialize

Conversation

@MashyBasker
Copy link
Contributor

Purpose

This PR adds a checker to detect insecure deserialization with pickle- backed or yaml library with user tainted data. This may cause potential Remote Code Execution vulnerabilities.

Signed-off-by: Maharshi Basu <basumaharshi10@gmail.com>
@vercel
Copy link

vercel bot commented Mar 19, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
Name Status Preview Comments Updated (UTC)
globstar ⬜️ Ignored (Inspect) Visit Preview Mar 19, 2025 6:15pm

@sourya-deepsource sourya-deepsource merged commit c7096a2 into DeepSourceCorp:master Mar 21, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants