Using pickle.loads() on Untrusted User Input Data
Flask views deserialize user data with pickle: data = pickle.loads(request.data). Pickle can execute arbitrary code during deserialization through __reduce__ method. Attackers craft malicious pickled objects executing commands. Common in session data, cache systems, or API endpoints accepting serialized data.