PT-2025-22916 · Pypi · Pypickle
Esharmaji
·
Published
2025-05-26
·
Updated
2025-05-26
·
CVE-2025-5174
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
erdogant pypickle versions 1.1.5 and earlier
Description
A vulnerability was found in erdogant pypickle, classified as problematic. The issue affects the
load function of the file pypickle/pypickle.py, leading to deserialization. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.Recommendations
For erdogant pypickle versions 1.1.5 and earlier, upgrade to version 2.0.0 to address this issue. As a temporary workaround, consider restricting access to the
load function of the pypickle/pypickle.py file until the upgrade is applied.Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pypickle