PT-2026-34048 · Pypi · Pycel

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2026-30108

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions pycel versions 1.0b30 and earlier
Description An insecure deserialization issue exists where the function from file() in the ExcelCompiler class passes pickle-backed input into pickle.load(). This allows a payload to be executed during the pickle.load() process before the object is rejected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-30108

Affected Products

Pycel