Lune

USENIX Security2026顶会

Toward Understanding the Security Implications in Python Configuration Files

Xinwei Yu, Zhenkai Zhang, Yuzhe Tang, Xing Gao

2026年份

摘要

Security incidents targeting open-source software have increased substantially in recent years, yet existing defenses primarily focus on analyzing source code while largely overlooking configuration files that define how software is built, installed, and executed. In this paper, we present an in-depth study of security risks in Python configuration files, analyzing five widely used formats across the project lifecycle. We focus on risks that exploit configuration files to silently redirect dependency resolution to attacker-controlled infrastructure or hijack benign commands. We design an automated framework and identify 39 configuration fields that can be exploited under realistic usage scenarios. We further demonstrate that existing malware detection tools fail to detect most of these risks. As mitigation, we develop ConfigScoper, which not only examines security-relevant fields but also employs multiple vulnerability detectors to identify potential malicious behaviors. We apply ConfigScoper in a measurement study analyzing millions of open-source Python projects on GitHub, and our empirical results show that exploitable risks already exist in real-world projects. Finally, we have responsibly disclosed the identified vulnerabilities to relevant stakeholders.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext f813a9b6-b95e-4e63-9cc5-cfaec8aead5b

它引用的顶会 Paper27

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖