CI Report:
https://ci-tests.linuxserver.io/linuxserver/sabnzbd/nightly-93546e5b-ls184/index.html
LinuxServer Changes:
No changes
Remote Changes:
Add SafeUnpickler to guard against pickle-attacks (#3585)
-
Add SafeUnpickler to guard against pickle-attacks
-
Harden pickle unpickler with explicit allowlist
The previous SafeUnpickler allowed any class from sabnzbd.* by wildcard, which could still enable deserialization attacks if a "gadget class" (e.g., with a malicious __del__ method) was present within our own package.
This commit renames the class to RestrictedUnpickler and changes its logic to only allow classes explicitly defined in _SAFE_GLOBALS. This significantly enhances security by preventing the unpickling of any unlisted classes, including those from within sabnzbd. Adds os.stat_result and sabnzbd.nzb.* classes to the allowlist for compatibility.