[Python-ideas] Security: remove "." from sys.path?

Greg Ewing greg.ewing at canterbury.ac.nz
Sat Jun 3 20:00:58 EDT 2017


Is this really much of a security issue? Seems to me that
for someone to exploit it, they would have to inject a
malicious .py file alongside one of my script files. If
they can do that, they can probably do all kinds of bad
things directly.

-- 
Greg


More information about the Python-ideas mailing list