The guardian angel for your codebase.
Find, validate, and fix vulnerabilities in code as it is written.
Get updatesOne finding, from scan to fix.
deva scan .NEW / full scanCRITICAL ledgerlens/views.py:87 ID: f_40f0dd7825c680fd34d51d04 deva.cwe-345.pickle-on-request-body | CWE-345 pickle.loads called directly on a request body / network input without a signature check. Either replace pickle with JSON, or verify a separate HMAC over the bytes before unpickling. deva validate f_40f0dd7825c680fd34d51d04 --llmvalidate-finding: 1/1 f_40f0dd7825c680fd34d51d04Verdict: Likely validConfidence: 99%Explanation: The reachable import endpoint passes raw request bytes directly to pickle.loads, with no signature verification shown. Deployment exposure is not established. deva suggest-fix f_40f0dd7825c680fd34d51d04 --llmsuggest-fix: 1/1 f_40f0dd7825c680fd34d51d04Verdict: Fix suggestedConfidence: 94%Proposed diff (read-only): --- a/ledgerlens/views.py +++ b/ledgerlens/views.py @@ -82,7 +82,7 @@ @bp.post("/report/import") def import_report(): - import pickle + import json from flask import jsonify - report = pickle.loads(request.data) + report = json.loads(request.data) return jsonify({"received": report}) Review redacted source lines before applying this proposed diff.Excerpt of a real run of the Deva CLI on LedgerLens, our demo app. Paths shortened.
We're building Deva now.
Get Deva CLI and the Deva Extension for VS Code now. Join our mailing list to get more updates.