{"id":"CVE-2005-2875","aliases":["GHSA-wcpc-f63g-x26q","PYSEC-2026-742"],"title":"Py2Play Unpickles Untrusted Objects","summary":"Py2Play Unpickles Untrusted Objects","severity":"high","vendor":"py2play","product":"py2play","ecosystem":"pip","affected":["py2play <= 0.1.8"],"published":"2022-05-01","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-wcpc-f63g-x26q","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2875"},{"url":"https://bugs.gentoo.org/show_bug.cgi?id=103524"},{"url":"https://web.archive.org/web/20040824010038/http://home.gna.org/oomadness/fr/slune/index.html"},{"url":"https://web.archive.org/web/20050213041706/http://soya.literati.org"},{"url":"https://web.archive.org/web/20161225000907/http://www.securityfocus.com/bid/14864"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=326976"},{"url":"http://www.debian.org/security/2005/dsa-856"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200509-09.xml"}],"tags":["osv","pip"],"epss":0.01906,"epssPercentile":0.78562,"ingestedAt":"2026-07-08T18:25:53.602Z","slug":"CVE-2005-2875","body":"## Overview\n\nPy2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes.\n\n## Affected packages\n\n- `py2play <= 0.1.8`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}