<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 09:51:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-328297</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328297</link>
      <description>EUVD-2026-328297</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328297</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53873</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53873</link>
      <description>&lt;p&gt;picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). Attackers can craft malicious pickle files calling profile.run(statement) to execute arbitrary Python code while picklescan reports zero security issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). Attackers can craft malicious pickle files calling profile.run(statement) to execute arbitrary Python code while picklescan reports zero security issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53873</guid>
    </item>
    <item>
      <title>GHSA-7wx9-6375-f5wh — PickleScan's profile.run blocklist mismatch allows exec() bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7wx9-6375-f5wh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;picklescan v1.0.3 blocks `profile.Profile.run` and `profile.Profile.runctx` but does NOT block the module-level `profile.run()` function. A malicious pickle calling `profile.run(statement)` achieves arbitrary code execution via `exec()` while picklescan reports 0 issues. This is because the blocklist entry `&amp;#34;Profile.run&amp;#34;` does not match the pickle global name `&amp;#34;run&amp;#34;`.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**High** — Direct code execution via `exec()` with zero scanner detection.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- picklescan v1.0.3 (latest — the profile entries were added in recent versions)
- Earlier versions also affected (profile not blocked at all)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;In `scanner.py` line 199, the blocklist entry for `profile` is:&lt;/p&gt;
&lt;p&gt;```python
&amp;#34;profile&amp;#34;: {&amp;#34;Profile.run&amp;#34;, &amp;#34;Profile.runctx&amp;#34;},
```&lt;/p&gt;
&lt;p&gt;When a pickle file imports `profile.run` (the module-level function), picklescan&amp;#39;s opcode parser extracts:
- `module = &amp;#34;profile&amp;#34;`
- `name = &amp;#34;run&amp;#34;`&lt;/p&gt;
&lt;p&gt;The blocklist check at line 414 is:&lt;/p&gt;
&lt;p&gt;```python
elif unsafe_filter is not None and (unsafe_filter == &amp;#34;*&amp;#34; or g.name in unsafe_filter):
```&lt;/p&gt;
&lt;p&gt;This checks: is `&amp;#34;run&amp;#34;` in `{&amp;#34;Profile.run&amp;#34;, &amp;#34;Profile.runctx&amp;#34;}`?&lt;/p&gt;
&lt;p&gt;**Answer: NO.** `&amp;#34;run&amp;#34; != &amp;#34;Profile.run&amp;#34;`. The string comparison is exact — there is no prefix/suffix matching.&lt;/p&gt;
&lt;p&gt;### What `profile.run()` Does&lt;/p&gt;
&lt;p&gt;```python
# From Python&amp;#39;s Lib/profile.py
def run(statement, filename=None, sort=-1):
    prof = Profile()
    try:
        prof.run(statement)  # Calls exec(statement)
    except SystemExit:
        pass
    ...…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;picklescan v1.0.3 blocks `profile.Profile.run` and `profile.Profile.runctx` but does NOT block the module-level `profile.run()` function. A malicious pickle calling `profile.run(statement)` achieves arbitrary code execution via `exec()` while picklescan reports 0 issues. This is because the blocklist entry `&amp;#34;Profile.run&amp;#34;` does not match the pickle global name `&amp;#34;run&amp;#34;`.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**High** — Direct code execution via `exec()` with zero scanner detection.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- picklescan v1.0.3 (latest — the profile entries were added in recent versions)
- Earlier versions also affected (profile not blocked at all)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;In `scanner.py` line 199, the blocklist entry for `profile` is:&lt;/p&gt;
&lt;p&gt;```python
&amp;#34;profile&amp;#34;: {&amp;#34;Profile.run&amp;#34;, &amp;#34;Profile.runctx&amp;#34;},
```&lt;/p&gt;
&lt;p&gt;When a pickle file imports `profile.run` (the module-level function), picklescan&amp;#39;s opcode parser extracts:
- `module = &amp;#34;profile&amp;#34;`
- `name = &amp;#34;run&amp;#34;`&lt;/p&gt;
&lt;p&gt;The blocklist check at line 414 is:&lt;/p&gt;
&lt;p&gt;```python
elif unsafe_filter is not None and (unsafe_filter == &amp;#34;*&amp;#34; or g.name in unsafe_filter):
```&lt;/p&gt;
&lt;p&gt;This checks: is `&amp;#34;run&amp;#34;` in `{&amp;#34;Profile.run&amp;#34;, &amp;#34;Profile.runctx&amp;#34;}`?&lt;/p&gt;
&lt;p&gt;**Answer: NO.** `&amp;#34;run&amp;#34; != &amp;#34;Profile.run&amp;#34;`. The string comparison is exact — there is no prefix/suffix matching.&lt;/p&gt;
&lt;p&gt;### What `profile.run()` Does&lt;/p&gt;
&lt;p&gt;```python
# From Python&amp;#39;s Lib/profile.py
def run(statement, filename=None, sort=-1):
    prof = Profile()
    try:
        prof.run(statement)  # Calls exec(statement)
    except SystemExit:
        pass
    ...…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7wx9-6375-f5wh</guid>
    </item>
    <item>
      <title>PYSEC-2026-455 — PickleScan's profile.run blocklist mismatch allows exec() bypass</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-455</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;picklescan v1.0.3 blocks `profile.Profile.run` and `profile.Profile.runctx` but does NOT block the module-level `profile.run()` function. A malicious pickle calling `profile.run(statement)` achieves arbitrary code execution via `exec()` while picklescan reports 0 issues. This is because the blocklist entry `&amp;#34;Profile.run&amp;#34;` does not match the pickle global name `&amp;#34;run&amp;#34;`.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**High** — Direct code execution via `exec()` with zero scanner detection.&lt;/p&gt;
&lt;p&gt;## Affected Versions
 
- picklescan v1.0.3 (latest — the profile entries were added in recent versions)
 - Earlier versions also affected (profile not blocked at all)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;In `scanner.py` line 199, the blocklist entry for `profile` is:&lt;/p&gt;
&lt;p&gt;```python
&amp;#34;profile&amp;#34;: {&amp;#34;Profile.run&amp;#34;, &amp;#34;Profile.runctx&amp;#34;},
```&lt;/p&gt;
&lt;p&gt;When a pickle file imports `profile.run` (the module-level function), picklescan&amp;#39;s opcode parser extracts:
- `module = &amp;#34;profile&amp;#34;`
- `name = &amp;#34;run&amp;#34;`&lt;/p&gt;
&lt;p&gt;The blocklist check at line 414 is:&lt;/p&gt;
&lt;p&gt;```python
elif unsafe_filter is not None and (unsafe_filter == &amp;#34;*&amp;#34; or g.name in unsafe_filter):
```&lt;/p&gt;
&lt;p&gt;This checks: is `&amp;#34;run&amp;#34;` in `{&amp;#34;Profile.run&amp;#34;, &amp;#34;Profile.runctx&amp;#34;}`?&lt;/p&gt;
&lt;p&gt;**Answer: NO.** `&amp;#34;run&amp;#34; != &amp;#34;Profile.run&amp;#34;`. The string comparison is exact — there is no prefix/suffix matching.&lt;/p&gt;
&lt;p&gt;### What `profile.run()` Does&lt;/p&gt;
&lt;p&gt;```python
# From Python&amp;#39;s Lib/profile.py
def run(statement, filename=None, sort=-1):
    prof = Profile()
    try:
        prof.run(statement)  # Calls exec(statement)
    except SystemExit:
        pass
    .…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;picklescan v1.0.3 blocks `profile.Profile.run` and `profile.Profile.runctx` but does NOT block the module-level `profile.run()` function. A malicious pickle calling `profile.run(statement)` achieves arbitrary code execution via `exec()` while picklescan reports 0 issues. This is because the blocklist entry `&amp;#34;Profile.run&amp;#34;` does not match the pickle global name `&amp;#34;run&amp;#34;`.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**High** — Direct code execution via `exec()` with zero scanner detection.&lt;/p&gt;
&lt;p&gt;## Affected Versions
 
- picklescan v1.0.3 (latest — the profile entries were added in recent versions)
 - Earlier versions also affected (profile not blocked at all)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;In `scanner.py` line 199, the blocklist entry for `profile` is:&lt;/p&gt;
&lt;p&gt;```python
&amp;#34;profile&amp;#34;: {&amp;#34;Profile.run&amp;#34;, &amp;#34;Profile.runctx&amp;#34;},
```&lt;/p&gt;
&lt;p&gt;When a pickle file imports `profile.run` (the module-level function), picklescan&amp;#39;s opcode parser extracts:
- `module = &amp;#34;profile&amp;#34;`
- `name = &amp;#34;run&amp;#34;`&lt;/p&gt;
&lt;p&gt;The blocklist check at line 414 is:&lt;/p&gt;
&lt;p&gt;```python
elif unsafe_filter is not None and (unsafe_filter == &amp;#34;*&amp;#34; or g.name in unsafe_filter):
```&lt;/p&gt;
&lt;p&gt;This checks: is `&amp;#34;run&amp;#34;` in `{&amp;#34;Profile.run&amp;#34;, &amp;#34;Profile.runctx&amp;#34;}`?&lt;/p&gt;
&lt;p&gt;**Answer: NO.** `&amp;#34;run&amp;#34; != &amp;#34;Profile.run&amp;#34;`. The string comparison is exact — there is no prefix/suffix matching.&lt;/p&gt;
&lt;p&gt;### What `profile.run()` Does&lt;/p&gt;
&lt;p&gt;```python
# From Python&amp;#39;s Lib/profile.py
def run(statement, filename=None, sort=-1):
    prof = Profile()
    try:
        prof.run(statement)  # Calls exec(statement)
    except SystemExit:
        pass
    .…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-455</guid>
    </item>
  </channel>
</rss>
