nextRound
TechnologiesCoding ProblemsBookmarksLearning PathsLogin
nextRound
TechnologiesCoding ProblemsBookmarksLearning PathsLogin
nextRound

AI-powered interview preparation platform. Practice with curated questions, mock interviews, and personalized learning paths to crack your dream tech interview.

Quick Links

  • Technologies
  • Mock Interviews
  • Saved Questions
  • Pricing

Company

  • About Us
  • Contact Us

Legal

  • Privacy Policy
  • Terms of Use

© 2026 nextRound. All rights reserved.

Questions
2 of 5
1How should sensitive credentials (API keys, passwords) be managed in a Python application rather than hardcoded?
2How can deserializing data with pickle from an untrusted source lead to remote code execution?
3Why is using eval() or exec() on untrusted input a serious security risk?
4What is SQL injection, and how do parameterized queries in Python's database libraries prevent it?
5What risks does using subprocess with shell=True and untrusted input introduce?
PythonPython
Basics
Control Flow and Functions
Data Structures
Comprehensions & Functional Programming
Iterators, Generators & Decorators
Object-Oriented Programming
Exception Handling & Debugging
Concurrency & Parallelism
Performance & Optimization
Testing
Security
Modules, Packaging & Environment
Type Hinting & Modern Python
System Design & Architecture with Python
Best Practices & Design Patterns
Edge Cases & Tricky Interview Questions
02 / 05

How can deserializing data with pickle from an untrusted source lead to remote code execution?

Difficulty: 8/10
Pickle, Deserialization, Remote Code Execution, Serialization

pickle's reduce can call arbitrary callables during unpickling, giving RCE

pickle is a Python-specific serialization format that can represent almost any object, including classes and functions. During unpickling, pickle reconstructs objects by calling constructors and the reduce protocol. An attacker can craft a byte stream whose reduce returns a callable such as os.system and arguments to execute. When the victim unpickles that stream, the callable runs immediately, before any validation you might add afterwards. There is no safe mode and no way to inspect a pickle before loading it that is guaranteed to be safe, because the payload only needs to be valid enough to reach the callable. The practical rule is simple: never unpickle data from an untrusted source. Use json, msgpack, protobuf, or another data-only format, and validate with a schema. If you must transfer Python objects, restrict them to trusted systems with network controls and authentication, and sign or encrypt the payload.

  1. 1

    Any callable reachable through reduce can be invoked during unpickling, not just os.system.

  2. 2

    Signing the pickle does not make it safe to load untrusted data; it only proves who sent it.

  3. 3

    Restricted unpicklers and find_class overrides are hardening measures, not guarantees.

  4. 4

    Alternatives: json for data, msgpack for compact binary, protobuf or Avro for schemas, and dataclasses for reconstructing typed objects.

  5. 5

    Common mistake: treating pickle as a general-purpose data format for caching or message queues that accept external input.

  6. 6

    Common mistake: assuming that a pickle you generated earlier is safe because you wrote it; if the storage or network is compromised, the payload can be replaced.

  7. 7

    Version note: pickle protocol 5 (3.8+) added out-of-band buffers but did not change the security model. The risk is the same across all protocols.

Scenario Questions

0-2 years experience

  1. 1You need to send data between two services. Why is pickle a bad choice for a public API?
  2. 2What happens if you unpickle a malicious payload?

2-5 years experience

  1. 1You use pickle for a Redis cache that stores session data. How do you make it safe?
  2. 2A teammate suggests signing pickles to make them safe. How do you respond?

5-8 years experience

  1. 1You need to migrate a system from pickle to json without downtime. How do you handle existing cached pickles?
  2. 2You must transfer complex Python objects between internal services over a network. What are your safe options?

8+ years experience

  1. 1Design a serialization layer for an internal platform that is safe, fast, and supports schema evolution across versions.
  2. 2Explain how to audit a large codebase for dangerous unpickling and enforce safe alternatives in CI.

Follow-up Questions

  • Why does signing a pickle not make it safe to load?
  • How would you design a secure cache that stores Python objects without pickle?
Sharethis question

Share via WhatsApp, X, Facebook, LinkedIn or copy link. Open Graph preview enabled.