<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:10:27 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-67748 — Fickling has Code Injection vulnerability via pty.spawn()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-67748</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; trailofbits fickling&lt;/p&gt;
&lt;p&gt;Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; trailofbits fickling&lt;/p&gt;
&lt;p&gt;Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-67748</guid>
    </item>
    <item>
      <title>GHSA-r7v6-mfhq-g3m2 — Fickling has Code Injection vulnerability via pty.spawn()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r7v6-mfhq-g3m2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: fickling&lt;/p&gt;
&lt;p&gt;## Fickling Assessment&lt;/p&gt;
&lt;p&gt;Based on the test case provided in the original report below, this bypass was caused by `pty` missing from our block list of unsafe module imports (as previously documented in #108), rather than the unused variable heuristic. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in https://github.com/trailofbits/fickling/pull/187.&lt;/p&gt;
&lt;p&gt;## Original report&lt;/p&gt;
&lt;p&gt;### Summary
An unsafe deserialization vulnerability in Fickling allows a crafted pickle file to bypass the &amp;#34;unused variable&amp;#34; heuristic, enabling arbitrary code execution. This bypass is achieved by adding a trivial operation to the pickle file that &amp;#34;uses&amp;#34; the otherwise unused variable left on the stack after a malicious operation, tricking the detection mechanism into classifying the file as safe.&lt;/p&gt;
&lt;p&gt;### Details
Fickling relies on the heuristic of detecting unused variables in the VM&amp;#39;s stack after execution. Opcodes like `REDUCE`, `OBJ`, and `INST`, which can be used for arbitrary code execution, leave a value on the stack that is often unused in malicious pickle files.
This vulnerability enables a bypass by modifying the pickle file to use this leftover variable. A simple way to achieve this is to add a `BUILD` opcode that, in effect, adds a `__setstate__` to the unused variable. This makes Fickling consider the variable &amp;#34;used,&amp;#34; thus failing to flag the malicious file.&lt;/p&gt;
&lt;p&gt;### PoC
The following is a disassembled view of a malicious pickle file that bypas…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: fickling&lt;/p&gt;
&lt;p&gt;## Fickling Assessment&lt;/p&gt;
&lt;p&gt;Based on the test case provided in the original report below, this bypass was caused by `pty` missing from our block list of unsafe module imports (as previously documented in #108), rather than the unused variable heuristic. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in https://github.com/trailofbits/fickling/pull/187.&lt;/p&gt;
&lt;p&gt;## Original report&lt;/p&gt;
&lt;p&gt;### Summary
An unsafe deserialization vulnerability in Fickling allows a crafted pickle file to bypass the &amp;#34;unused variable&amp;#34; heuristic, enabling arbitrary code execution. This bypass is achieved by adding a trivial operation to the pickle file that &amp;#34;uses&amp;#34; the otherwise unused variable left on the stack after a malicious operation, tricking the detection mechanism into classifying the file as safe.&lt;/p&gt;
&lt;p&gt;### Details
Fickling relies on the heuristic of detecting unused variables in the VM&amp;#39;s stack after execution. Opcodes like `REDUCE`, `OBJ`, and `INST`, which can be used for arbitrary code execution, leave a value on the stack that is often unused in malicious pickle files.
This vulnerability enables a bypass by modifying the pickle file to use this leftover variable. A simple way to achieve this is to add a `BUILD` opcode that, in effect, adds a `__setstate__` to the unused variable. This makes Fickling consider the variable &amp;#34;used,&amp;#34; thus failing to flag the malicious file.&lt;/p&gt;
&lt;p&gt;### PoC
The following is a disassembled view of a malicious pickle file that bypas…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r7v6-mfhq-g3m2</guid>
    </item>
  </channel>
</rss>
