PT-2025-22916 · Pypi · Pypickle

Esharmaji

·

Published

2025-05-26

·

Updated

2025-05-26

·

CVE-2025-5174

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions erdogant pypickle versions 1.1.5 and earlier
Description A vulnerability was found in erdogant pypickle, classified as problematic. The issue affects the load function of the file pypickle/pypickle.py, leading to deserialization. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Recommendations For erdogant pypickle versions 1.1.5 and earlier, upgrade to version 2.0.0 to address this issue. As a temporary workaround, consider restricting access to the load function of the pypickle/pypickle.py file until the upgrade is applied.

Exploit

Fix

Deserialization of Untrusted Data

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-5174
GHSA-5QWJ-342R-H886
PYSEC-2025-45

Affected Products

Pypickle