[issue41998] JSON Encoder Injection Using Indent

2020-10-10 Thread Dustin Moriarty
Dustin Moriarty added the comment: Sounds good. If this is the design intent, then we can close the issue. -- resolution: -> not a bug stage: -> resolved status: open -> closed ___ Python tracker <https://bugs.python.or

[issue41998] JSON Encoder Injection Using Indent

2020-10-10 Thread Dustin Moriarty
New submission from Dustin Moriarty : It is possible to inject data while encoding json when a string is passed to the indent argument. Here is an example of an injection attack. ```python import json data = {"a": "original data"} indent = '"b": "inj