Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fickling's static analyzer fails to flag several high-risk Python modules that can be used for arbitrary code execution. Malicious pickles importing these modules will not be detected as unsafe, allowing attackers to bypass Fickling's primary static safety checks. This issue has been patched in version 0.1.7.
Metrics
Affected Vendors & Products
References
History
Sat, 10 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fickling's static analyzer fails to flag several high-risk Python modules that can be used for arbitrary code execution. Malicious pickles importing these modules will not be detected as unsafe, allowing attackers to bypass Fickling's primary static safety checks. This issue has been patched in version 0.1.7. | |
| Title | Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist | |
| Weaknesses | CWE-184 CWE-502 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-10T01:35:18.152Z
Reserved: 2026-01-07T21:50:39.534Z
Link: CVE-2026-22609
No data.
Status : Received
Published: 2026-01-10T02:15:50.050
Modified: 2026-01-10T02:15:50.050
Link: CVE-2026-22609
No data.
OpenCVE Enrichment
No data.