> Whereas there are no known security holes in pickle.


it's fairly trivial to construct a pickle string that calls eval
or os.system with arbitrary arguments.


