CVE-2026-22609High▾ TwilightFickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.6%
#Fickling's assessment
ctypes, importlib, runpy, code and multiprocessing were added the list of unsafe imports (https://github.com/trailofbits/fickling/commit/9a2b3f89bd0598b528d62c10a64c1986fcb09f66, https://github.com/trailofbits/fickling/commit/eb299b453342f1931c787bcb3bc33f3a03a173f9, https://github.com/trailofbits/fickling/commit/29d5545e74b07766892c1f0461b801afccee4f91, https://github.com/trailofbits/fickling/commit/b793563e60a5e039c5837b09d7f4f6b92e6040d1, https://github.com/trailofbits/fickling/commit/b793563e60a5e039c5837b09d7f4f6b92e6040d1).
The unsafe_imports() method in Fickling's static analyzer fails to flag several high-risk Python modules that can be used for arbitrary code execution. Malicious pickles importing these modules will not be detected as unsafe, allowing attackers to bypass Fickling's primary static safety checks.
In fickling/fickle.py lines 866-884, the unsafe_imports() method checks imported modules against a hardcoded tuple:
def unsafe_imports(self) -> Iterator[ast.Import | ast.ImportFrom]:
for node in self.properties.imports:
if node.module in (
"__builtin__", "__builtins__", "builtins", "os", "posix", "nt",
"subprocess", "sys", "builtins", "socket", "pty", "marshal", "types",
):
yield node
This list is incomplete. The following dangerous modules are NOT detected:
Since ctypes is part of the Python standard library, it also bypasses the NonStandardImports analysis.
from fickling.fickle import Pickled
from fickling.analysis import check_safety, Severity
# Pickle that imports ctypes.pythonapi (allows arbitrary code execution)
# PROTO 4, GLOBAL 'ctypes pythonapi', STOP
payload = b'\x80\x04cctypes\npythonapi\n.'
pickled = Pickled.load(payload)
results = check_safety(pickled)
print(f"Severity: {results.severity.name}")
print(f"Is safe: {results.severity == Severity.LIKELY_SAFE}")
# Output: Severity is LIKELY_SAFE or low - the ctypes import is not flagged
# A truly malicious pickle using ctypes could execute arbitrary code
Security Bypass (Confidentiality, Integrity, Availability)
An attacker can craft a malicious pickle that:
ctypes to gain arbitrary memory accessctypes.pythonapi or ctypes.CDLL to execute arbitrary codeThis undermines the core purpose of Fickling as a pickle safety scanner.
fickling < 0.1.7Upgrade to a patched release:
fickling 0.1.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-22606HighFickling has a bypass via runpy.run_path() and runpy.run_module()
CVE-2026-22607HighFickling Blocklist Bypass: cProfile.run()
CVE-2026-22612HighFickling vulnerable to detection bypass due to "builtins" blindness
CVE-2026-22608HighFickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
CVE-2025-67747HighFickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list