PT-2026-55672 · Pypi · Picklescan
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
picklescan versions prior to 0.0.29
Description
The software fails to detect malicious pickle payloads that utilize the
lib2to3.pgen2.grammar.Grammar.loads function within the reduce method. This flaw allows remote code execution, as attackers can craft pickle files containing dangerous code that evades detection and executes during the pickle.load() deserialization process. Deserialization is the process of converting a data format back into an object.Recommendations
Update to version 0.0.29 or later.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Picklescan