Python Deserialization: pickle, PyYAML and the __reduce__ Trap
pickle.loads on untrusted bytes runs code because __reduce__ returns a callable that executes at load time, and yaml.load without SafeLoader builds arbitrary objects. Here is the minimal exploit, and why safe_load and JSON are the fix.