Pickle Deserialization RCE via Model Upload Endpoint
2d ago · 4 min read · Link: https://www.ratctf.com/challenges/synapse-lab
This challenge revolves around a classic but still heavily abused primitive: unsafe Python pickle deserialization exposed through a model upload API