PT-2025-51355 · Fickling · Fickling

CVE-2025-67748

·

Published

2025-12-15

·

Updated

2026-07-10

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Fickling versions prior to 0.1.6
Description Fickling, a Python pickling decompiler and static analyzer, contained a bypass related to missing unsafe module imports. Specifically, the pty module was not included in the block list, leading to pickles utilizing pty.spawn() being incorrectly identified as safe. This impacted users and systems relying on Fickling for pickle file security assessments.
Recommendations Update to Fickling version 0.1.6 or later.

Exploit

Fix

Code Injection

Incomplete List of Disallowed Inputs

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67748
GHSA-R7V6-MFHQ-G3M2
PYSEC-2025-113

Affected Products

Fickling