Skip to main content
Glama
dynamic-code-injection.py294 B
# The following code is vulnerable to arbitrary code execution because it runs dynamic Python code based on untrusted data. from flask import request @app.route("/") def example(): operation = request.args.get("operation") eval(f"product_{operation}()") # Noncompliant return "OK"

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/michoo/security_mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server