The Glass Sandbox – The Complexity of Python Sandboxing
ID: b2242b27-844a-5ce3-ac94-29f92d940264
STIX ID: report--b2242b27-844a-5ce3-ac94-29f92d940264
Feed Name: Checkmarx Zero
Threat Score
**Executive summary:** This article demonstrates how Python's object hierarchy and dunder attribute traversal can defeat scope-based sandboxes, using pandas.eval() as a concrete example to achieve remote code execution; it warns that blocklists are brittle and advocates avoiding eval-like constructs, applying OS-level isolation/segmentation, and using SAST and safer parsers to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
