diff --git a/test.py b/test.py index 360ad4a..fc55e01 100644 --- a/test.py +++ b/test.py @@ -10,7 +10,15 @@ google_api_token = "AIzaSyAQfxPJiounkhOjODEO5ZieffeBv6yft2Q" gh_PAT = "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" +def insecure_eval(user_input): + # BAD: using eval on untrusted input + result = eval(user_input) + return result + # main if __name__ == '__main__': print('hello Github world') + + user_input = input("Enter something: ") + print(insecure_eval(user_input))