Preliminary research
Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Python's recursive attribute and item setters let a user-supplied key path walk from an object to its class, module globals, function defaults and closure cells, so one nested update rewrites the runtime. The talk gives the first taxonomy - get primitive crossed with set primitive, six types, five new - and its Pyrl taint analyser finds 47 zero-days and 7 CVEs across 671,475 repos and packages. Polluting os.environ['BROWSER'] makes the webbrowser module a universal RCE gadget.
Record
- Researcher
- Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang and Yinzhi Cao
- Format
- Whitepaper
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang and Yinzhi Cao, first published at the original source. Preserved copies are kept so the citation survives its host.