Количество 2
Количество 2
CVE-2025-67748
Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.
GHSA-r7v6-mfhq-g3m2
Fickling has Code Injection vulnerability via pty.spawn()
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-67748 Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-r7v6-mfhq-g3m2 Fickling has Code Injection vulnerability via pty.spawn() | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу