PT-2026-51510 · Pypi · Picklescan

·

CVE-2026-56315

·

Published

2026-03-03

·

Updated

2026-07-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions picklescan versions prior to 1.0.4
Description The software fails to block at least seven Python standard library modules, including uuid, osx support, aix support, pyrepl.pager, and imaplib. This oversight exposes eight functions that allow direct arbitrary command execution. Attackers can bypass safety validation by crafting malicious pickle files that import these unblocked modules to achieve remote code execution.
Recommendations Update to version 1.0.4.

Exploit

Fix

RCE

Incomplete List of Disallowed Inputs

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56315
GHSA-G38G-8GR9-H9XP

Affected Products

Picklescan