7

Is numexpr safe again malicious attack?

I'm considering using it in a web application, to evaluate user input text.

I've also considered using PLY, ASTEVAL and Pyparsing.

PeeHaa
  • 71,436
  • 58
  • 190
  • 262
user744629
  • 1,961
  • 1
  • 18
  • 27
  • I am also very curious about [numexpr](https://code.google.com/p/numexpr/) and [asteval](http://newville.github.io/asteval/)? Hasn't anyone an opinion or experience about these packages? There's no end to the [eval is dangerous](http://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html) talk. [SymPy](http://docs.sympy.org/dev/index.html) may also be susceptible to malicious attack. – Mark Mikofski Aug 07 '13 at 03:18

0 Answers0