> If you pickle data from an untrusted source . . . and then later unpickle it
That is not exactly right. The risk is when you unpickle data that was pickled by someone else or that was tampered with after you pickled it.
That is not exactly right. The risk is when you unpickle data that was pickled by someone else or that was tampered with after you pickled it.
https://docs.python.org/3/library/pickle.html
https://blog.nelhage.com/2011/03/exploiting-pickle/ (referenced from https://cwe.mitre.org/data/definitions/502.html#REF-467)