🎄 Join our Annual Holiday wargame and win prizes!


Class Pollution Vulnerability in Python - A New Type of Security Vulnerability

14/03/2024

The challenge shows a variant of JavaScript’s Prototype Pollution in Python. Specially crafted JSON input can tamper with existing classes and modify their behaviour.

I have implemented this vulnerability the popular FastAPI framework.

:point_right: Link to the challenge: Class Pollution.py

Give it a try and let’s us know what you think.

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more