CVE-2025-67748High· 7.8▾ TwilightFickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by pty missing from the block list of unsafe module imports. This led to unsafe pickles based on pty.spawn() being incorrectly flagged as LIKELY_SAFE, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.
fickling < 0.1.6Upgrade past the affected range:
fickling 0.1.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-22606HighFickling has a bypass via runpy.run_path() and runpy.run_module()
CVE-2026-22607HighFickling Blocklist Bypass: cProfile.run()
CVE-2025-67747High· 7.8Fickling is a Python pickling decompiler and static analyzer
CVE-2026-22609HighFickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
CVE-2026-22612HighFickling vulnerable to detection bypass due to "builtins" blindness
CVE-2026-22608HighFickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection