The full Lisp reader is in effect when we use read-from-string, so anything could happen and using it can lead to vulnerabilities issues. Example:
(read-from-string "#.(print \"you're dead!\")")
;; => "you're dead!"
;; compare with:
(read-from-string "(print \"you're dead!\")")
;; => (PRINT "you're dead")
;; => the PRINT was not executed.
Don't use it with input coming from the outside. That being said, it is possible to disable the #. reader macro:
(let ((cl:*read-eval* nil))
(read-from-string "…"))
;; => #<SB-INT:SIMPLE-READER-ERROR "can't read #. while *READ-EVAL* is NIL" {10091A1663}>.
and better, to use a standard readtable and prevent other reader macros:
(with-standard-io-syntax
(let ((cl:*read-eval* nil))
(read-from-string "…")))
The full Lisp reader is in effect when we use
read-from-string, so anything could happen and using it can lead to vulnerabilities issues. Example:Don't use it with input coming from the outside. That being said, it is possible to disable the
#.reader macro:and better, to use a standard readtable and prevent other reader macros: