Insecure Deserialization - Hunter Knowledge Base
SkillDocs & knowledgeKnowledge base for finding insecure deserialization - untrusted data fed to object-deserialization APIs that can trigger RCE or object injection via gadget chains. Use when hunting deserialization issues. CWE-502, OWASP A08:2021-Software and Data Integrity Failures.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Insecure Deserialization - Hunter Knowledge Base skill
What this skill tells your AI
The instructions your AI receives, as published by dmdhrumilmistry/security-harness in skills/sh-kb-deserialization/SKILL.md and read by ahel’s review.
Deserializing attacker-controlled bytes into live objects can execute code during reconstruction (magic methods / gadget chains) or corrupt application state. Confirmed native-object deserialization of untrusted input is typically critical (RCE).
Sinks by ecosystem (grep targets)
- Python:
pickle.load(s),cPickle,yaml.load(withoutSafeLoader,jsonpickle.decode,shelve,dill,marshal.loads,pandas.read_pickle,numpy.load(allow_pickle=True). - Java:
ObjectInputStream.readObject(,readUnshared, XMLDecoder, XStream (default), Kryo, SnakeYAMLnew Yaml().load(, Jackson polymorphic typing (enableDefaultTyping/@JsonTypeInfo), FastjsonparseObjectwith autotype. - PHP:
unserialize(on user input (POP chains via__wakeup/__destruct). - Ruby:
Marshal.load(,YAML.load((Psych, pre-safe),Ojin object mode. - .NET:
BinaryFormatter.Deserialize,LosFormatter,NetDataContractSerializer,TypeNameHandlingin JSON. - Node:
node-serializeunserialize(,funcster,serialize-javascriptmisuse,vmon decoded input.
Detection recipe
graft grep "pickle.load|yaml.load\(|readObject|unserialize\(|Marshal.load|BinaryFormatter|TypeNameHandling|enableDefaultTyping" --json.- Trace the input to the deserializer: request body/cookie/header, cache, queue message, uploaded file, or a signed token whose signature isn't verified before deserialization.
- Check for a safe variant (see filters). If the raw/native deserializer processes untrusted bytes, flag.
Payloads / PoC
- Python pickle: a class with
__reduce__returning(os.system, ('id',))- describe the gadget; do not ship a live malicious blob. - Java: reference
ysoserialgadget families (CommonsCollections, etc.) conceptually - the PoC is that the endpoint deserializes attacker bytes with vulnerable classpath gadgets present. - PHP: craft a serialized object of a class with a dangerous
__destruct/__wakeup(POP chain). - Detection without RCE: send a malformed/DoS payload or an object of an unexpected type and observe type-confusion behavior.
False-positive filters
- Safe loaders:
yaml.safe_load,SafeLoader; JSON (json.loads,JSON.parseof plain data) with no polymorphic typing; protobuf/avro/thrift schema-bound decoders;pickleof a trusted, integrity-checked source only (e.g. a file the app itself wrote, signature-verified before load). - Deserializer restricted by an allowlist of classes /
ObjectInputFilter(Java) / customfind_class. - Data is signed+verified (HMAC) before deserialization and the key is secret.
CWE / OWASP / severity
CWE-502. OWASP A08:2021. Untrusted native deserialization with reachable gadgets -> critical; object injection with limited impact -> high.
Chaining hints
Deserialization RCE -> read secrets, pivot; often reachable via access-control gaps (an endpoint that
accepts serialized state); cache/queue poisoning feeds it a stored payload (second-order).
Mitigation
Never deserialize untrusted data with native/polymorphic deserializers. Prefer schema-bound formats (JSON
without type info, protobuf). If unavoidable, sign+verify integrity with a secret key and restrict to an
allowlist of expected classes; disable polymorphic typing (Jackson TypeNameHandling.None, remove XStream
default). Keep gadget-prone libraries patched.
Signals
- GitHub stars
- 26
- Forks
- 9
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
sh-kb-deserialization- Source
- github.com/dmdhrumilmistry/security-harness