Code injection in rope
Critical severity
GitHub Reviewed
Published
Jul 26, 2018
to the GitHub Advisory Database
•
Updated Oct 21, 2024
Description
Published to the GitHub Advisory Database
Jul 26, 2018
Reviewed
Jun 16, 2020
Last updated
Oct 21, 2024
base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.
References