appsec.fyi

Python — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Python: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 216 of 216 curated resources. Browse all 216 Python resources →

Problem Framing

Python's pervasive use in application development, from web services and data science to automation and AI, makes it a critical target for security practitioners. Its dynamic nature, extensive ecosystem of third-party libraries, and ease of use, while beneficial for development velocity, introduce a complex attack surface. Attackers exploit these characteristics to achieve various objectives, including remote code execution (RCE), data exfiltration, privilege escalation, and supply chain compromises. Understanding the common vulnerabilities and attack vectors within the Python ecosystem is paramount for building secure applications.

Core Mechanics

At its core, Python's security landscape is shaped by its language features and how developers interact with its vast library ecosystem. Key areas of concern include:

Notable Techniques

Several specific techniques have been observed in the wild or identified as significant risks:

Detection & Prevention

Mitigating Python-specific security risks requires a multi-layered approach:

Tooling

A range of tools are available to aid Python application security practitioners:

Recent Developments

The threat landscape for Python applications is constantly evolving:

Where to Go Deeper

For practitioners seeking to deepen their understanding and proficiency:

Sources cited in this guide

  1. Escalating Deserialization Attacks in Python — frichetten.com
  2. Exploiting Python Pickles - David Hamann — davidhamann.de
  3. Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign — wiz.io
  4. How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM — snyk.io
  5. Command injection in Python: examples and prevention — snyk.io
  6. Ultralytics AI Library Hacked via GitHub for Cryptomining — wiz.io
  7. PyPI Supply Chain Attack: Colorama and Colorizr Name Confusion — checkmarx.com
  8. Hunting Leaked PyPI Tokens: 62 Live, 125 Packages Exposed — blog.gitguardian.com
  9. CVE-2025-68664: Critical LangChain Flaw Enables Secret Extraction — socradar.io
  10. CVE-2026-22607: Fickling Python RCE Vulnerability — sentinelone.com
  11. CVE-2026-21226: Azure Core Python Library RCE Vulnerability — sentinelone.com
  12. Insecure Deserialization in Python: Attack Techniques and Secure Coding — redfoxsec.com
  13. CVE-2025-56005: PLY RCE Vulnerability — sentinelone.com
  14. Python Software Foundation - Python 3.11.0a3 to 3.15.0b2 — bishopfox.com
  15. How I Found a High-Severity Directory Traversal in Flask-Admin — infosecwriteups.com
  16. BadHost - One character and your AI agent switches sides — korben.info
  17. SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files — thehackernews.com
  18. Compromised Flutter package on pub.dev contains XCSSET malware — aikido.dev
  19. Malicious PyPI Packages Deliver SilentSync RAT — zscaler.com
  20. Script Injection and Data Theft: Python Data Analysis Tool Compromised — heise.de
  21. Compromised LiteLLM PyPI Package Delivers Credential Stealer — sonatype.com
  22. durabletask: TeamPCP's Latest PyPi Compromise — wiz.io
  23. Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! — aikido.dev
  24. Code injection in Python: examples and prevention — snyk.io
  25. Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) — snyk.io
  26. Linux Kernel Elevation of Privilege Vulnerability — hkcert.org
  27. "Copy Fail": Linux root in all major distributions with 732 bytes of Python — heise.de
  28. New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions — thehackernews.com
  29. Exposing 4 Critical Vulnerabilities in Python PickleScan | Sonatype — sonatype.com
  30. PyTorch Users at Risk: 3 Zero-Day PickleScan Vulnerabilities | JFrog — jfrog.com
  31. HN Security - My Semgrep C/C++ ruleset is ready for prime time again — hnsecurity.it
  32. Python SAST Tools: Free & Paid Solutions for Secure Code Analysis — bito.ai
  33. Bandit: Python Static Application Security Testing Guide — dev.to
  34. Flaws in Google APK for Python Unlock Agent-to-Agent Attack — darkreading.com
  35. How To Keep A Secret in Python Apps — talkpython.fm
  36. A Python prompt into a running process: debugging with Manhole — pythonspeed.com
  37. A Python prompt into a running process: debugging with Manhole — pythonspeed.com
  38. GitHub - cle-b/httpdbg: A tool for Python developers to easily debug the HTTP(S) client requests in a Python program. — github.com
  39. GitHub - wapiti-scanner/wapiti: Web vulnerability scanner written in Python3 — github.com
  40. Show HN: Drawbridge – Drop-In SSRF Protection for Python | Hacker News — news.ycombinator.com
  41. fortra/impacket — github.com
  42. Usage Scapy 2.4.5. documentation — scapy.readthedocs.io
  43. Reversing Pickles with r2pickledec — blog.doyensec.com
  44. Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14% — snyk.io
  45. OWASP Pygoat — owasp.org
  46. OWASP Pygoat | OWASP Foundation — owasp.org
  47. Leaking internal headers in Flask Ninja with deserialization — eval.blog
  48. JDownloader Website Supply Chain Attack: Installers Replaced with Python RAT Malware (May 2026) — rescana.com
  49. Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure — thehackernews.com
  50. Critical SQL Injection Vulnerability in Django (CVE-2025-64459) — endorlabs.com
  51. Insecure Deserialization in Python | Semgrep — semgrep.dev
  52. Django Security Best Practices: A Comprehensive Guide for Software Engineers - Corgea - Home — corgea.com
  53. GitHub - danialhalo/SqliSniper: Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers — github.com
  54. GitHub - xnl-h4ck3r/knoxnl: This is a python wrapper around the amazing KNOXSS API by Brute Logic — github.com
  55. How to Implement OAuth 2.0 Login for Python Flask Web Server Applications — atrium.ai
  56. Writing fast async HTTP requests in Python — blog.jonlu.ca
  57. How to Brute-Force SSH Servers in Python — thepythoncode.com
  58. Quickstart Web3.py 5.23.1 documentation — web3py.readthedocs.io
  59. Python Scripting for Hackers Part 1: Getting Started — hackers-arise.com
  60. A Beginners Guide to Python for Cybersecurity — coursereport.com
  61. Elliptic Curve Keys Python and Hazmat — medium.com
  62. RSA Signatures Python and Hazmat — medium.com
  63. Accessing the Dark Web with Python — link.medium.com
  64. 10 common security gotchas in Python and how to avoid them — link.medium.com
📚 This guide is synthesized from the full text of resources curated in the Python library, and refreshed as new material is added.