PT-2026-2228 · Fickling · Fickling

·

CVE-2026-22608

·

Published

2026-01-09

·

Updated

2026-07-07

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Fickling versions prior to 0.1.7
Description Fickling, a Python pickling decompiler and static analyzer, does not explicitly block the ctypes and pydoc modules in versions prior to 0.1.7. Combining these modules can lead to Remote Code Execution (RCE), even while the scanner reports the file as LIKELY SAFE. The issue arises because existing pickle scanning tools, such as picklescan, also do not block pydoc.locate.
Recommendations Update to Fickling version 0.1.7 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22608
GHSA-5HVC-6WX8-MVV4
PYSEC-2026-1369

Affected Products

Fickling