PT-2026-2229 · Fickling · Fickling

Mldangelo

·

Published

2026-01-09

·

Updated

2026-01-10

·

CVE-2026-22609

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Fickling versions prior to 0.1.7
Description Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe imports() method within Fickling’s static analyzer does not identify several high-risk Python modules that could be used for arbitrary code execution. This allows malicious pickles importing these modules to bypass Fickling’s safety checks.
Recommendations Update Fickling to version 0.1.7 or later.

Exploit

Fix

Incomplete List of Disallowed Inputs

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-22609
GHSA-Q5QQ-MVFM-J35X

Affected Products

Fickling