Review agent · Web & injection

Unsafe deserialization

Checks whether untrusted bytes are deserialized by a mechanism that can build arbitrary objects.

jobs/restore.py1blob = request.get_data()2state = pickle.loads(blob)3cache.put(state.key, state)Deserwhat this review answerspickle, unserialize or unsafe YAML?Does input cross a trust boundary?Safe loader or allow-listed types?$ verdict REAL ISSUE$ fix JSON with a schema▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

Deserializing attacker-controlled data with pickle, Java serialization or PHP unserialize can lead straight to remote code execution. The 2015 Apache Commons Collections gadget chain showed how far one library could reach.

The same call is perfectly safe on trusted, internal data, so the deciding question is the trust boundary. This agent answers it and tells you when a safe loader is already in use.

What it checks

  • pickle.loads, marshal, non-safe yaml.load
  • Java ObjectInputStream and PHP unserialize
  • Type-resolving JSON or XML deserializers
  • Whether the input crosses a trust boundary

When it marks a finding as a likely false positive

  • The data source is trusted and internal
  • A safe loader such as yaml.safe_load is used

The fix it suggests

  • A safe format such as JSON with a schema
  • yaml.safe_load or allow-listed types
  • Signed data when objects must round-trip

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Is pickle always a vulnerability?

Only when the bytes can come from someone untrusted. Loading your own cache file is usually fine; loading a request body or an uploaded file is not.

Related agents

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Unsafe deserialization agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free