BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Get Set\, Exploit! Unveiling Python Class Pollution 
 In-the-Wild\n   Tags: DEF CON Official Talk | Demo ðŸ’» | Tool ðŸ›  | Expl
 oit ðŸª²\n   When: Saturday\, Aug 8\, 15:00 - 15:59 PDT\n   Where: LVCCW L
 evel 1 Hall 3 906 (Main Track 3) and DCTV-3 - [1]Map\n\n   Description:\n\
 n   Python is widely used in LLM applications and agent frameworks. Its\n 
   ease of use comes from two core features: a uniform object model and\n  
  dynamic reflection\, which unfortunately also enable an emerging\n   vuln
 erability class: Python class pollution. To date\, with only one\n   CVE a
 nd a handful of synthetic examples since its first disclosure in\n   2023\
 , what is known is merely the tip of the iceberg\, the real threat\n   run
 s far deeper into the Python ecosystem.\n\n   In this talk\, we introduce 
 the first complete taxonomy of this\n   vulnerability class\, built from t
 wo object-resolution primitives and\n   three object-assignment primitives
 \, which together yield six types.\n   Only one was previously known.\n\n 
   Building on this taxonomy\, we design and implement Pyrl\, the first\n  
  automated framework for detecting Python class pollution via a novel\n   
 static analysis technique named operational taint analysis. Applying\n   P
 yrl to over 600\,000 GitHub and PyPI packages\, we found 47 exploitable\n 
   zero-days in Azure CLI\, Taipy\, ComfyUI\, Google Mesop\, HuggingFace\n 
   Smolagents\, and others. Through live case studies\, we show how class\n
    pollution can be weaponized into token exfiltration\, authentication\n 
   bypass\, stored XSS\, sandbox escape\, and RCE. Most importantly\,we\n  
  demonstrate that even the weakest typeâ€”one previously unknownâ€”can\n  
  still lead to critical impact in practice.\n\n   Speakers:Gavin Zhong\,Zh
 engyu Liu\,Jianjia Yu\n\n   SpeakerBio:  Gavin Zhong\, Johns Hopkins Unive
 rsity\n\n   Jiacheng (Gavin) Zhong is a security researcher\, focusing on 
 AI system\n   security\, program analysis\, and identity security. He rece
 ntly\n   completed his M.S. in Security Informatics at Johns Hopkins\n   U
 niversity\, where his work was accepted to IEEE S&P 2026. Gavin has\n   re
 ported over 30 CVEs in widely used open-source projects. He is also\n   an
  active CTF player with r3kapig\, an international team ranked top 3\n   w
 orldwide.\n\n   SpeakerBio:  Zhengyu Liu\, Johns Hopkins University\n\n   
 Zhengyu Liu is a third-year PhD student in Computer Science at Johns\n   H
 opkins University. His research focuses on web and software security\n   v
 ia program analysis. His work received Distinguished Paper (S&P\n   â€™25)
 \, Honorable Mention (USENIX â€™25)\, and Best Student Paper\n   (ICICS â€
 ™22). He is a DEF CON speaker and is a member of CTF team\n   TheHackersCr
 ew.\n\n   SpeakerBio:  Jianjia Yu\, Johns Hopkins University\n\n   Jianjia
  Yu is a PhD student at Johns Hopkins University\, advised by\n   Prof. Yi
 nzhi Cao. Her research focuses on security and privacy in web\n   and mobi
 le ecosystems using program analysis techniques. Her work has\n   received
  Distinguished Paper Awards at CCS '23 and S&P '25\, and an\n   Honorable 
 Mention at USENIX Security '25. She has discovered over 40\n   zero-day vu
 lnerabilities and uncovered privacy leaks affecting\n   millions of users 
 across browser extensions and mobile applications.\n\n   '\n\n   1. #LVCCW
 _Level1_Hall3\n\n\n
DTEND:20260808T225900Z
DTSTART:20260808T220000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Get Set\, Exploit! Unveiling Python Class Pollution In-the-Wild
END:VEVENT
END:VCALENDAR
