Discussion about this post

User's avatar
Your Bro's avatar

Scrapling critical: unsafe checkpoint deserialization (pickle.loads) can execute code

- Code: scrapling/spiders/checkpoint.py:74

- Risk: if crawldir is user-controlled/shared, a malicious checkpoint.pkl gives arbitrary code execution on resume.

No posts

Ready for more?