Rule Information
Tags
pythondeserializationpicklerceuntrusted-dataowasp-a08cwe-502remote-code-executioncriticalsecurityintra-procedural
CWE References
CVE References
Experiment with the vulnerable code and security rule below. Edit the code to see how the rule detects different vulnerability patterns.
pathfinder scan --ruleset python/PYTHON-DESER-001 --project .Common questions about Unsafe Pickle Deserialization
New feature
The Unsafe Pickle Deserialization rule runs in CI and posts inline review comments on the exact lines — no dashboard, no SARIF viewer.