<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T09:51:14.795177+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-328297</id>
    <title>EUVD-2026-328297</title>
    <updated>2026-10-08T09:51:14.798281+00:00</updated>
    <content>EUVD-2026-328297</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-328297"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53873</id>
    <title>fkie_cve-2026-53873</title>
    <updated>2026-10-08T09:51:14.798317+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). Attackers can craft malicious pickle files calling profile.run(statement) to execute arbitrary Python code while picklescan reports zero security issues.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7wx9-6375-f5wh</id>
    <title>GHSA-7wx9-6375-f5wh — PickleScan's profile.run blocklist mismatch allows exec() bypass</title>
    <updated>2026-10-08T09:51:14.798349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: picklescan</p>
<p>## Summary</p>
<p>picklescan v1.0.3 blocks `profile.Profile.run` and `profile.Profile.runctx` but does NOT block the module-level `profile.run()` function. A malicious pickle calling `profile.run(statement)` achieves arbitrary code execution via `exec()` while picklescan reports 0 issues. This is because the blocklist entry `"Profile.run"` does not match the pickle global name `"run"`.</p>
<p>## Severity</p>
<p>**High** — Direct code execution via `exec()` with zero scanner detection.</p>
<p>## Affected Versions</p>
<p>- picklescan v1.0.3 (latest — the profile entries were added in recent versions)
- Earlier versions also affected (profile not blocked at all)</p>
<p>## Details</p>
<p>### Root Cause</p>
<p>In `scanner.py` line 199, the blocklist entry for `profile` is:</p>
<p>```python
"profile": {"Profile.run", "Profile.runctx"},
```</p>
<p>When a pickle file imports `profile.run` (the module-level function), picklescan's opcode parser extracts:
- `module = "profile"`
- `name = "run"`</p>
<p>The blocklist check at line 414 is:</p>
<p>```python
elif unsafe_filter is not None and (unsafe_filter == "*" or g.name in unsafe_filter):
```</p>
<p>This checks: is `"run"` in `{"Profile.run", "Profile.runctx"}`?</p>
<p>**Answer: NO.** `"run" != "Profile.run"`. The string comparison is exact — there is no prefix/suffix matching.</p>
<p>### What `profile.run()` Does</p>
<p>```python
# From Python's Lib/profile.py
def run(statement, filename=None, sort=-1):
    prof = Profile()
    try:
        prof.run(statement)  # Calls exec(statement)
    except SystemExit:
        pass
    ...…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7wx9-6375-f5wh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-455</id>
    <title>PYSEC-2026-455 — PickleScan's profile.run blocklist mismatch allows exec() bypass</title>
    <updated>2026-10-08T09:51:14.798413+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: picklescan</p>
<p>## Summary</p>
<p>picklescan v1.0.3 blocks `profile.Profile.run` and `profile.Profile.runctx` but does NOT block the module-level `profile.run()` function. A malicious pickle calling `profile.run(statement)` achieves arbitrary code execution via `exec()` while picklescan reports 0 issues. This is because the blocklist entry `"Profile.run"` does not match the pickle global name `"run"`.</p>
<p>## Severity</p>
<p>**High** — Direct code execution via `exec()` with zero scanner detection.</p>
<p>## Affected Versions
 
- picklescan v1.0.3 (latest — the profile entries were added in recent versions)
 - Earlier versions also affected (profile not blocked at all)</p>
<p>## Details</p>
<p>### Root Cause</p>
<p>In `scanner.py` line 199, the blocklist entry for `profile` is:</p>
<p>```python
"profile": {"Profile.run", "Profile.runctx"},
```</p>
<p>When a pickle file imports `profile.run` (the module-level function), picklescan's opcode parser extracts:
- `module = "profile"`
- `name = "run"`</p>
<p>The blocklist check at line 414 is:</p>
<p>```python
elif unsafe_filter is not None and (unsafe_filter == "*" or g.name in unsafe_filter):
```</p>
<p>This checks: is `"run"` in `{"Profile.run", "Profile.runctx"}`?</p>
<p>**Answer: NO.** `"run" != "Profile.run"`. The string comparison is exact — there is no prefix/suffix matching.</p>
<p>### What `profile.run()` Does</p>
<p>```python
# From Python's Lib/profile.py
def run(statement, filename=None, sort=-1):
    prof = Profile()
    try:
        prof.run(statement)  # Calls exec(statement)
    except SystemExit:
        pass
    .…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-455"/>
  </entry>
</feed>
