From da7a5bd9cb872bd11c06d6ae933e88a7354d9df7 Mon Sep 17 00:00:00 2001 From: Ana Scolari <127357173+apsscolari@users.noreply.github.com> Date: Mon, 15 Sep 2025 22:04:33 -0700 Subject: [PATCH] Implement insecure_eval function for user input Added insecure_eval function that uses eval on user input. --- test.py | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/test.py b/test.py index 360ad4a..fc55e01 100644 --- a/test.py +++ b/test.py @@ -10,7 +10,15 @@ google_api_token = "AIzaSyAQfxPJiounkhOjODEO5ZieffeBv6yft2Q" gh_PAT = "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" +def insecure_eval(user_input): + # BAD: using eval on untrusted input + result = eval(user_input) + return result + # main if __name__ == '__main__': print('hello Github world') + + user_input = input("Enter something: ") + print(insecure_eval(user_input))