diff --git a/vulnerable_deserialization.py b/vulnerable_deserialization.py index 4d443d1..9d48693 100644 --- a/vulnerable_deserialization.py +++ b/vulnerable_deserialization.py @@ -1,4 +1,4 @@ -import pickle +import json import yaml import marshal from flask import Flask, request @@ -9,7 +9,7 @@ def load_data(): data = request.data - obj = pickle.loads(data) + obj = json.loads(data) return str(obj)