Lune

S&P2026顶会

The First Large-Scale Systematic Study of Python Class Pollution Vulnerability

Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang, Yinzhi Cao

2026年份

摘要

Class pollution is a recently discovered, yet underexplored Python vulnerability that allows attackers to pollute unintended runtime objects by exploiting the class-based inheritance model and reflection mechanism. Before this paper, only two real-world vulnerabilities related to class pollutionincluding one reported to the Common Vulnerabilities and Exposures (CVE) database-were discovered. Furthermore, there was no existing tool capable of detecting such vulnerabilities, let alone a systematic study of vulnerable code patterns, exploitation techniques, and real-world prevalence.

In this paper, we design and implement Pyrl, the first framework for detecting class pollution vulnerabilities in realworld applications via a novel, static operational taint analysis.

Our key insight is that class pollution consists of two types of vulnerable code primitives-"get" and "set"-for fetching and setting items and attributes. Different combinations of these primitives (two types of "get"s and three "set"s) further lead to six unique vulnerability types according to our first taxonomy of class pollution. Pyrl's operational taint analysis tracks attacker-controlled inputs on these primitives and their combinations using fine-grained, operational taint labels that are initiated, transformed, propagated, and merged according to the analysis context.

We applied Pyrl to over half a million real-world Python programs from GitHub and PyPI, resulting in the detection of 47 zero-day, exploitable class pollutions. Our findings include critical vulnerabilities in widely used applications, such as Azure CLI by Microsoft and Mesop by Google, both of which have been acknowledged and patched. We have responsibly reported all identified vulnerabilities to the corresponding developers-who fixed five of them-and CVE Numbering Authorities (CNAs)-who assigned seven CVE identifiers.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper23

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖