<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 04:53:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329199</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329199</link>
      <description>EUVD-2026-329199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329199</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56315</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56315</link>
      <description>&lt;p&gt;picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attackers can craft malicious pickle files importing these unblocked modules to achieve remote code execution while bypassing picklescan&amp;#39;s safety validation entirely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attackers can craft malicious pickle files importing these unblocked modules to achieve remote code execution while bypassing picklescan&amp;#39;s safety validation entirely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56315</guid>
    </item>
    <item>
      <title>GHSA-g38g-8gr9-h9xp — PickleScan has multiple stdlib modules with direct RCE not in blocklist</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g38g-8gr9-h9xp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;picklescan v1.0.3 (latest) does not block at least 7 Python standard library modules that provide direct arbitrary command execution or code evaluation. A malicious pickle file importing these modules is reported as having 0 issues (CLEAN scan). This enables remote code execution that bypasses picklescan entirely.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**Critical** (CVSS 9.8) — Direct RCE with zero scanner detection. Affects all deployments relying on picklescan, including HuggingFace Hub.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- picklescan &amp;lt;= 1.0.3 (all versions including latest)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Unblocked RCE Modules&lt;/p&gt;
&lt;p&gt;| Module | Function | RCE Mechanism | picklescan Result |
|--------|----------|--------------|-------------------|
| `uuid` | `_get_command_stdout(cmd, *args)` | `subprocess.Popen((cmd,) + args)` | CLEAN |
| `_osx_support` | `_read_output(cmdstring)` | `os.system()` via temp file | CLEAN |
| `_osx_support` | `_find_build_tool(toolname)` | Command injection via `%s` | CLEAN |
| `_aix_support` | `_read_cmd_output(cmdstring)` | `os.system()` | CLEAN |
| `_pyrepl.pager` | `pipe_pager(text, cmd)` | `subprocess.Popen(cmd, shell=True)` | CLEAN |
| `_pyrepl.pager` | `tempfile_pager(text, cmd)` | `os.system(cmd + ...)` | CLEAN |
| `imaplib` | `IMAP4_stream(command)` | `subprocess.Popen(command, shell=True)` | CLEAN |
| `test.support.script_helper` | `assert_python_ok(*args)` | Spawns `python` subprocess | CLEAN |&lt;/p&gt;
&lt;p&gt;All 8 functions are in Python&amp;#39;s standard library and importable on all platforms.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;picklescan v1.0.3 (latest) does not block at least 7 Python standard library modules that provide direct arbitrary command execution or code evaluation. A malicious pickle file importing these modules is reported as having 0 issues (CLEAN scan). This enables remote code execution that bypasses picklescan entirely.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**Critical** (CVSS 9.8) — Direct RCE with zero scanner detection. Affects all deployments relying on picklescan, including HuggingFace Hub.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- picklescan &amp;lt;= 1.0.3 (all versions including latest)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Unblocked RCE Modules&lt;/p&gt;
&lt;p&gt;| Module | Function | RCE Mechanism | picklescan Result |
|--------|----------|--------------|-------------------|
| `uuid` | `_get_command_stdout(cmd, *args)` | `subprocess.Popen((cmd,) + args)` | CLEAN |
| `_osx_support` | `_read_output(cmdstring)` | `os.system()` via temp file | CLEAN |
| `_osx_support` | `_find_build_tool(toolname)` | Command injection via `%s` | CLEAN |
| `_aix_support` | `_read_cmd_output(cmdstring)` | `os.system()` | CLEAN |
| `_pyrepl.pager` | `pipe_pager(text, cmd)` | `subprocess.Popen(cmd, shell=True)` | CLEAN |
| `_pyrepl.pager` | `tempfile_pager(text, cmd)` | `os.system(cmd + ...)` | CLEAN |
| `imaplib` | `IMAP4_stream(command)` | `subprocess.Popen(command, shell=True)` | CLEAN |
| `test.support.script_helper` | `assert_python_ok(*args)` | Spawns `python` subprocess | CLEAN |&lt;/p&gt;
&lt;p&gt;All 8 functions are in Python&amp;#39;s standard library and importable on all platforms.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g38g-8gr9-h9xp</guid>
    </item>
    <item>
      <title>PYSEC-2026-4134 — PickleScan has multiple stdlib modules with direct RCE not in blocklist</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-4134</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;picklescan v1.0.3 (latest) does not block at least 7 Python standard library modules that provide direct arbitrary command execution or code evaluation. A malicious pickle file importing these modules is reported as having 0 issues (CLEAN scan). This enables remote code execution that bypasses picklescan entirely.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**Critical** (CVSS 9.8) — Direct RCE with zero scanner detection. Affects all deployments relying on picklescan, including HuggingFace Hub.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- picklescan &amp;lt;= 1.0.3 (all versions including latest)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Unblocked RCE Modules&lt;/p&gt;
&lt;p&gt;| Module | Function | RCE Mechanism | picklescan Result |
|--------|----------|--------------|-------------------|
| `uuid` | `_get_command_stdout(cmd, *args)` | `subprocess.Popen((cmd,) + args)` | CLEAN |
| `_osx_support` | `_read_output(cmdstring)` | `os.system()` via temp file | CLEAN |
| `_osx_support` | `_find_build_tool(toolname)` | Command injection via `%s` | CLEAN |
| `_aix_support` | `_read_cmd_output(cmdstring)` | `os.system()` | CLEAN |
| `_pyrepl.pager` | `pipe_pager(text, cmd)` | `subprocess.Popen(cmd, shell=True)` | CLEAN |
| `_pyrepl.pager` | `tempfile_pager(text, cmd)` | `os.system(cmd + ...)` | CLEAN |
| `imaplib` | `IMAP4_stream(command)` | `subprocess.Popen(command, shell=True)` | CLEAN |
| `test.support.script_helper` | `assert_python_ok(*args)` | Spawns `python` subprocess | CLEAN |&lt;/p&gt;
&lt;p&gt;All 8 functions are in Python&amp;#39;s standard library and importable on all platforms.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;picklescan v1.0.3 (latest) does not block at least 7 Python standard library modules that provide direct arbitrary command execution or code evaluation. A malicious pickle file importing these modules is reported as having 0 issues (CLEAN scan). This enables remote code execution that bypasses picklescan entirely.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**Critical** (CVSS 9.8) — Direct RCE with zero scanner detection. Affects all deployments relying on picklescan, including HuggingFace Hub.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- picklescan &amp;lt;= 1.0.3 (all versions including latest)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Unblocked RCE Modules&lt;/p&gt;
&lt;p&gt;| Module | Function | RCE Mechanism | picklescan Result |
|--------|----------|--------------|-------------------|
| `uuid` | `_get_command_stdout(cmd, *args)` | `subprocess.Popen((cmd,) + args)` | CLEAN |
| `_osx_support` | `_read_output(cmdstring)` | `os.system()` via temp file | CLEAN |
| `_osx_support` | `_find_build_tool(toolname)` | Command injection via `%s` | CLEAN |
| `_aix_support` | `_read_cmd_output(cmdstring)` | `os.system()` | CLEAN |
| `_pyrepl.pager` | `pipe_pager(text, cmd)` | `subprocess.Popen(cmd, shell=True)` | CLEAN |
| `_pyrepl.pager` | `tempfile_pager(text, cmd)` | `os.system(cmd + ...)` | CLEAN |
| `imaplib` | `IMAP4_stream(command)` | `subprocess.Popen(command, shell=True)` | CLEAN |
| `test.support.script_helper` | `assert_python_ok(*args)` | Spawns `python` subprocess | CLEAN |&lt;/p&gt;
&lt;p&gt;All 8 functions are in Python&amp;#39;s standard library and importable on all platforms.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-4134</guid>
    </item>
  </channel>
</rss>
