{"id":"GHSA-5v23-73v4-w2fp","title":"Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO` ","summary":"Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO` ","severity":"high","cvss":7.5,"cwe":["CWE-22"],"vendor":"picklescan","product":"picklescan","ecosystem":"pip","affected":["picklescan < 0.0.35"],"patched":["picklescan 0.0.35"],"published":"2026-06-17","updated":"2026-06-18","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-5v23-73v4-w2fp","references":[{"url":"https://github.com/mmaitre314/picklescan/security/advisories/GHSA-9726-w42j-3qjr"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53872"},{"url":"https://www.vulncheck.com/advisories/picklescan-arbitrary-file-read-via-unsafe-pickle-deserialization"},{"url":"https://github.com/advisories/GHSA-5v23-73v4-w2fp"}],"tags":["ghsa","pip"],"ingestedAt":"2026-06-29T14:31:47.198Z","slug":"GHSA-5v23-73v4-w2fp","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-9726-w42j-3qjr. This link is maintained to preserve external references.\n\n### Original Description\npicklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read arbitrary server files by chaining io.FileIO and urllib.request.urlopen. Attackers can bypass RCE-focused blocklists to exfiltrate sensitive data like /etc/passwd to external servers.\n\n## Affected packages\n\n- `picklescan < 0.0.35`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `picklescan 0.0.35`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}