Preliminary research
Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Python's recursive attribute and item setters let a user-supplied key path walk from an object to its class, module globals, function defaults and closure cells, so one nested update rewrites the runtime. The talk gives the first taxonomy - get primitive crossed with set primitive, six types, five new - and its Pyrl taint analyser finds 47 zero-days and 7 CVEs across 671,475 repos and packages. Polluting os.environ['BROWSER'] makes the webbrowser module a universal RCE gadget.
Record
- Researcher
- Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang and Yinzhi Cao
- Published by
- media.defcon.org
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang and Yinzhi Cao, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .