▣ Remote Code Execution
Deserialization, template injection, unsafe pipelines — getting a shell where there shouldn't be one.
[docker lab] unsafe-pipeline
Practice identifying and containing an unsafe document pipeline. Run it locally to practice the proof of concept in an isolated environment.
docker compose -f labs/rce up --buildaurora@hack:~$ ls ./cases/rce
▲ Critical9 min read
Trusted CSV Chat to Remote Pickle Deserialization
A trusted CSV-analysis workflow let an AI enrich a query with a remote model file, leading pandas to deserialize an attacker-controlled pickle and execute code.
#pandas#pickle#deserialization#ai-agent#ssrf
▲ Critical10 min read
Malicious Python Artifact Executed by an AI Sandbox
A hidden artifact-upload endpoint accepted a Python code artifact that the AI later executed with unrestricted builtins inside an isolated but overexposed sandbox.
#python#artifacts#sandbox#ai-agent#rce
other classes: arbitrary-file-read · prompt-injection-role-confusion · sqli · system-prompt-exfiltration