T09 · Insecure Skill Coding Practices
- Location
rqns_agent.py:31- Finding
Unsafe Pickle Deserialization Enables Arbitrary Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
rqns_agent.py:31-34
Vulnerability Type: Unsafe deserialization
Risk Level: HighVulnerable Code
python if Path("data/qtable_pretrained.pkl").exists(): import pickle with open("data/qtable_pretrained.pkl", "rb") as f: self.Q = pickle.load(f)Technical Analysis
pickle.load()is capable of invoking attacker-selected Python callables while reconstructing serialized objects. It must therefore never be used on files whose provenance and integrity are not guaranteed.The file path is relative to the process's current working directory rather than a trusted package directory. An attacker who can create or replace
data/qtable_pretrained.pklin that directory can supply a malicious pickle. The payload is automatically deserialized whenContextualBanditAgentis instantiated, without authenticity verification, schema validation, or type validation.Attack Path
- The attacker obtains write access to the application's working directory or otherwise controls the directory from which the application is launched.
- The attacker creates
data/qtable_pretrained.pklcontaining a malicious pickle whose reconstruction method executes a selected command or Python callable. - The application creates
ConcreteRQNSPipeline, which initializesContextualBanditAgent. - The existence check succeeds and
pickle.load(f)deserializes the malicious object. - The embedded operation executes with the privileges and environmental access of the Python process.
Impact Assessment
Successful exploitation provides arbitrary code execution under the account running the application. The attacker could read or modify files available to that account, access process environment data, alter application behavior, invoke local programs, or establish additional persistence where operating-system permissions permit. The scope is limited by the process's pr ...[truncated 32 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace pickle with a non-executable serialization format, such as JSON, or use a NumPy format loaded with
allow_pickle=False. - Resolve the model path relative to a trusted, read-only package or configuration directory rather than the current working directory.
- Validate the loaded object's dimensions, numeric data type, finite values, and maximum permitted size before assigning it to
self.Q. - Protect model artifacts with deployment-time integrity controls, such as a cryptographic signature or a hash stored in trusted configuration.
- Restrict file ownership and write permissions so that untrusted users cannot replace model artifacts.
- If legacy pickle support is unavoidable, migrate trusted data offline rather than deserializing arbitrary pickle files in the live application. A custom restricted unpickler reduces some risks but is not preferable to eliminating pickle.
- Replace pickle with a non-executable serialization format, such as JSON, or use a NumPy format loaded with
