Insecure deserialization: data that runs as code

Some serialisation formats can describe objects with behaviour. Loading one from an untrusted source lets whoever wrote it decide what runs while it loads.

Example

Vulnerable
import pickle

@app.post("/import")
def import_settings():
    settings = pickle.loads(request.data)
    return apply(settings)
Fixed
import json

@app.post("/import")
def import_settings():
    settings = json.loads(request.data)
    validate(settings)  # check the shape and the types
    return apply(settings)

How it happens

Python's pickle, yaml.load without a safe loader, Java's ObjectInputStream, PHP's unserialize and node-serialize can all construct objects whose setup code runs during decoding. Session data, cache entries, import features and message queues are typical places where such data arrives from outside.

How to fix it

Use a data-only format.

  • Use JSON and validate the shape and types
  • Use yaml.safe_load instead of yaml.load
  • Never unpickle data a user can influence; sign data you must round-trip
  • Remove node-serialize and similar libraries

How RepoVerse finds it

  • HighRequest input is deserialised into live objects

    Serialisers that rebuild functions run attacker-chosen code while decoding.

    data flow · CWE-502

  • HighUntrusted data deserialised into objects

    `pickle`, `marshal` and bare `yaml.load` construct arbitrary Python objects, which means arbitrary code, from the bytes they are given.

    pattern

  • HighUntrusted data deserialised into objects

    `node-serialize`, `serialize-javascript` unserialise and `vm.runInNewContext` reconstruct behaviour, not just data.

    pattern

Questions

Is JSON.parse safe?
JSON.parse only builds plain data, so it cannot run code. The result still needs validation, and merging it into objects without care can cause prototype pollution.
Is signing serialized data enough?
Signing with a server-side key prevents tampering, as long as the key stays secret. Data-only formats remain the safer default.

Related

Updated 2026-10-11