The First Large-Scale Systematic Study of Python Class Pollution Vulnerability
Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang, Yinzhi Cao
Abstract
Class pollution is a recently discovered, yet underexplored Python vulnerability that allows attackers to pollute unintended runtime objects by exploiting the class-based inheritance model and reflection mechanism. Before this paper, only two real-world vulnerabilities related to class pollutionincluding one reported to the Common Vulnerabilities and Exposures (CVE) database-were discovered. Furthermore, there was no existing tool capable of detecting such vulnerabilities, let alone a systematic study of vulnerable code patterns, exploitation techniques, and real-world prevalence.
In this paper, we design and implement Pyrl, the first framework for detecting class pollution vulnerabilities in realworld applications via a novel, static operational taint analysis.
Our key insight is that class pollution consists of two types of vulnerable code primitives-"get" and "set"-for fetching and setting items and attributes. Different combinations of these primitives (two types of "get"s and three "set"s) further lead to six unique vulnerability types according to our first taxonomy of class pollution. Pyrl's operational taint analysis tracks attacker-controlled inputs on these primitives and their combinations using fine-grained, operational taint labels that are initiated, transformed, propagated, and merged according to the analysis context.
We applied Pyrl to over half a million real-world Python programs from GitHub and PyPI, resulting in the detection of 47 zero-day, exploitable class pollutions. Our findings include critical vulnerabilities in widely used applications, such as Azure CLI by Microsoft and Mesop by Google, both of which have been acknowledged and patched. We have responsibly reported all identified vulnerabilities to the corresponding developers-who fixed five of them-and CVE Numbering Authorities (CNAs)-who assigned seven CVE identifiers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3ca663f6-76cd-48c5-8827-100e339159bbBuilds on23
- Detecting Node.js prototype pollution vulnerabilities via object lookup analysisSong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoFSE 2021 · 49 citations
- Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven EcosystemYulun Wu, Zeliang Yu, Ming Wen, Qiang Li et al.ICSE 2023 · 41 citations
- Abusing Hidden Properties to Attack the Node.js EcosystemFeng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang et al.USENIX Security 2021 · 35 citations
- Improving Java Deserialization Gadget Chain Mining via Overriding-Guided Object GenerationSicong Cao, Xiaobing Sun, Xiaoxue Wu, Lili Bo et al.ICSE 2023 · 24 citations
- Undefined-oriented Programming: Detecting and Chaining Prototype Pollution Gadgets in Node.js Template Engines for Malicious ConsequencesZhengyu Liu, Kecheng An, Yinzhi CaoS&P 2024 · 17 citations
Related papers
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.jsMikhail Shcherbakov, Musard Balliu, Cristian-Alexandru StaicuUSENIX Security 2023
- PyRTFuzz: Detecting Bugs in Python Runtimes via Two-Level Collaborative FuzzingWen Li, Haoran Yang, Xiapu Luo, Long Cheng et al.CCS 2023 · 14 citations
- An Empirical Study on Static Application Security Testing (SAST) Tools for PythonZhuohang Liu, Zhi Wang, Haotong Liu, Wanpeng LiICSE 2026
- Follow My Flow: Unveiling Client-Side Prototype Pollution Gadgets from One Million Real-World WebsitesZifeng Kang, Muxi Lyu, Zhengyu Liu, Jianjia Yu et al.S&P 2025
- Bullseye: Detecting Prototype Pollution in NPM Packages with Proof of Concept ExploitsTariq Houis, Shaoqi Jiang, Mohammad Mannan, Amr YoussefNDSS 2026 · 2 citations
