logo

Playing with Python Pickle #1

ID: 73d23fee-e33f-5c4f-b247-ad9939767b90

STIX ID: report--73d23fee-e33f-5c4f-b247-ad9939767b90

Feed Name: SensePost Blog

Threat Score
60/100

Date Published: 2010-11-09

Date Updated: 2026-04-29

...
...

This report explains the security risks of deserializing untrusted Python Pickle data, demonstrates how Pickle opcode streams can invoke arbitrary code (including via overwritten memcached entries), and provides opcode-level examples and replication steps to illustrate how an attacker could achieve remote code execution by injecting malicious Pickle objects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.