Skip to main content
Run any Skill in Manus
with one click

python-prototype-pollution

Python 原型链污染(属性注入/Class Pollution)检测与利用。当目标为 Python Web 应用(Flask/Sanic/Django/FastAPI)且存在递归合并(merge)、深度属性设置(pydash.set_)、JSON 配置更新接口时使用。覆盖污染入口识别、__globals__链构造、Flask SECRET_KEY/Jinja2定界符/searchpath污染、pydash路径过滤绕过、Sanic污染链、RCE/文件读取/权限提升利用

Stars1,429
Forks226
UpdatedApril 25, 2026 at 06:36
File Explorer
6 files
SKILL.md
readonly