Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2020-14343-lab — Controlled vulnerability research and reproduction lab for CVE-2020-14343 in PyYAML | Kitploit
Tools/GitHubGitHub/saina15/cve-2020-14343-lab
Vulnerability ScannersContainer SecurityDynamic Analysis (Sandboxing)Vulnerability AnalysisExploitationSecurity VirtualizationPenetration TestingPapers & ResearchLearning & EducationLabs & Practice
GitHub
2020 days agoNot yet reviewed
saina15/cve-2020-14343-lab

cve-2020-14343-lab

Controlled vulnerability research and reproduction lab for CVE-2020-14343 in PyYAML

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2020-14343 – PyYAML Unsafe YAML Loading Lab

1. Project Overview

This project demonstrates CVE-2020-14343 in a controlled and isolated Docker environment.

The lab contains two environments:

  • A vulnerable environment using PyYAML 5.3.1
  • A patched environment using PyYAML 5.4 and yaml.safe_load()

The lab demonstrates the complete vulnerability lifecycle:

  1. Deploy the vulnerable application.
  2. Identify the vulnerable PyYAML version.
  3. Reproduce the vulnerability using a controlled YAML payload.
  4. Detect the vulnerable version using an automated script.
  5. Upgrade to the fixed version.
  6. Test the same payload against the patched application.
  7. Verify that the malicious YAML is rejected.

The reproduction payload used in this lab is intentionally harmless and only prints a test marker.

2. CVE Information

PropertyDetails
CVECVE-2020-14343
ProductPyYAML
Affected versionsVersions before 5.4
Fixed version5.4
Vulnerability typeImproper Input Validation (CWE-20)
SeverityCritical
Attack surfaceYAML input processed using vulnerable loading functionality
CVSS9.3 (CVSS v4, GitHub Advisory)

Root Cause

The vulnerability occurs when untrusted YAML input is processed using vulnerable PyYAML loading functionality.

PyYAML versions before 5.4 allowed specially crafted YAML tags, including Python-specific tags such as:

!!python/object/new

to reach object construction functionality when FullLoader was used.

A malicious YAML document can therefore cause unintended Python code execution.

The issue was related to an incomplete fix for an earlier PyYAML vulnerability.

PyYAML 5.4 fixed CVE-2020-14343 by moving arbitrary Python tags to UnsafeLoader.

For applications processing untrusted YAML, this lab also uses yaml.safe_load() as a secure loading approach.

3. Lab Architecture

The lab contains two isolated Docker services:

                         Host Machine
                              |
                 +------------+------------+
                 |                         |
                 v                         v
          Vulnerable App             Patched App
          localhost:5000             localhost:5001
                 |                         |
            PyYAML 5.3.1             PyYAML 5.4
            FullLoader               SafeLoader
                 |                         |
                 v                         v
          Payload executes          Payload rejected

Services

ServiceHost PortContainer PortPyYAMLPurpose
vulnerable500050005.3.1Vulnerable environment
patched500150005.4Remediated environment

4. Repository Structure

cve-2020-14343-lab/
├── vulnerable/
│   ├── app.py
│   ├── Dockerfile
│   └── requirements.txt
├── patched/
│   ├── app.py
│   ├── Dockerfile
│   └── requirements.txt
├── exploit/
│   └── reproduce.py
├── detection/
│   └── detect.py
├── screenshots/
│   ├── 01-docker-compose-running.png
│   ├── 02-vulnerable-detection.png
│   ├── 03-patched-detection.png
│   ├── 04a-vulnerable-request.png
│   ├── 04b-vulnerable-execution-log.png
│   └── 05-patched-exploit-blocked.png
├── blog/
│   └── CVE-2020-14343-Technical-Blog.pdf
├── docker-compose.yml
├── README.md
└── .gitignore

Directory Description

File/DirectoryPurpose
vulnerable/app.pyFlask application using vulnerable YAML loading
vulnerable/DockerfileBuilds the vulnerable Docker image
vulnerable/requirements.txtPins PyYAML to 5.3.1
patched/app.pyFlask application using secure YAML loading
patched/DockerfileBuilds the patched Docker image
patched/requirements.txtPins PyYAML to 5.4
exploit/reproduce.pyReproduces the vulnerability using a controlled payload
detection/detect.pyChecks the PyYAML version inside a Docker container
docker-compose.ymlBuilds and runs both environments
screenshots/Contains evidence captured during the lab
blog/Contains the 800–1200 word technical blog PDF

5. Prerequisites

The following software is required:

  • Docker Desktop
  • Docker Compose
  • Python 3.x
  • Git

Docker Desktop must be running before starting the lab.

The vulnerable application is intentionally exposed only on the local machine through Docker port mappings.

6. Lab Setup

Step 1: Start the Lab

From the project root directory, run:

docker compose up --build -d

Step 2: Verify the Containers

Run:

docker compose ps

Both services should show Up.

Step 3: Verify the Vulnerable Application

Open:

http://127.0.0.1:5000

Expected response:

{
  "message": "CVE-2020-14343 vulnerable YAML parser"
}

Step 4: Verify the Patched Application

Open:

http://127.0.0.1:5001

Expected response:

{
  "message": "CVE-2020-14343 patched YAML parser"
}

7. Starting, Stopping and Rebuilding the Lab

Start

docker compose up -d

Stop

docker compose down

Build and Start

docker compose up --build -d

Check Running Services

docker compose ps

View Vulnerable Application Logs

docker logs cve-vulnerable

View Patched Application Logs

docker logs cve-patched

8. Vulnerability Reproduction

The vulnerable application exposes a /parse endpoint that accepts YAML input.

The vulnerable environment uses:

  • PyYAML 5.3.1
  • yaml.FullLoader

The reproduction script is located at:

exploit/reproduce.py

Run the Exploit

The vulnerable application is available at:

http://127.0.0.1:5000/parse

Run:

python exploit/reproduce.py

The script sends a controlled YAML payload containing a Python-specific YAML tag.

Expected Result

In the vulnerable environment, the payload is accepted and the application returns an HTTP 200 response.

The controlled test marker:

CVE-2020-14343-TEST

is executed inside the vulnerable application container.

The execution can be verified using:

docker logs cve-vulnerable

Expected log output includes:

CVE-2020-14343-TEST

This demonstrates code execution through the vulnerable YAML loading behavior.

Safety

The reproduction payload is intentionally harmless. It only prints a test marker and does not modify the host system, access credentials, access sensitive data, interact with external systems, or perform destructive actions.

9. Vulnerability Detection

The detection script is located at:

detection/detect.py

The script checks the PyYAML version installed inside the specified Docker container.

The fixed version is:

5.4

Detect the Vulnerable Environment

Run:

python detection/detect.py cve-vulnerable

Expected result:

PyYAML installed version: 5.3.1
Fixed version: 5.4
STATUS: VULNERABLE
Reason: PyYAML version is older than 5.4.

Detect the Patched Environment

Run:

python detection/detect.py cve-patched

Expected result:

PyYAML installed version: 5.4
Fixed version: 5.4
STATUS: PATCHED
Reason: PyYAML version is 5.4 or newer.

Detection Logic

Docker Container
       |
       v
   docker exec
       |
       v
  Import PyYAML
       |
       v
Read yaml.__version__
       |
       v
 Compare with 5.4
       |
       +----------------------+
       |                      |
     < 5.4                  >= 5.4
       |                      |
       v                      v
  VULNERABLE                PATCHED

The script queries the installed PyYAML version from the target container.

10. Remediation

The vulnerable environment uses:

PyYAML==5.3.1

The patched environment uses:

PyYAML==5.4
Download Tool