Skip to content

Should an XKCD easter egg that introduces a vulnerability in CPython be removed from core distro? #144938

@fproulx-boostsecurity

Description

@fproulx-boostsecurity

An XKCD comic easter egg was added to CPython back in 2008 (https://github.com/python/cpython/blob/main/Lib/antigravity.py)

This enables a Living Off The Pipeline technique (https://boostsecurityio.github.io/lotp/tool/python). I question the fact that this joke remains in core distro.

Metadata

Metadata

Assignees

No one assigned

    Labels

    pendingThe issue will be closed if no feedback is providedtype-securityA security issue

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions