PT-2026-2229 · Fickling · Fickling

·

CVE-2026-22609

·

Published

2026-01-09

·

Updated

2026-07-07

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Fickling versions prior to 0.1.7
Description Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe imports() method within Fickling’s static analyzer does not identify several high-risk Python modules that could be used for arbitrary code execution. This allows malicious pickles importing these modules to bypass Fickling’s safety checks.
Recommendations Update Fickling to version 0.1.7 or later.

Exploit

Fix

Deserialization of Untrusted Data

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22609
GHSA-Q5QQ-MVFM-J35X
PYSEC-2026-1372

Affected Products

Fickling