This tutorial explores the security vulnerabilities associated with Python's pickle module, demonstrating how it can be exploited for remote code execution by crafting malicious serialized objects. It emphasizes the critical warning never to unpickle data from untrusted sources, illustrating the risk with a practical example involving a Flask web application and a reverse shell payload.
https://davidhamann.de/2020/04/05/exploiting-python-pickle/
Post #119
833