PT-2026-7636 · Diskcache · Diskcache

CVE-2025-69872

·

Published

2025-01-01

·

Updated

2026-07-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DiskCache (python-diskcache) versions through 5.6.3
Description DiskCache (python-diskcache) through version 5.6.3 utilizes Python pickle for serialization by default. An attacker who has write access to the cache directory can execute arbitrary code when a victim application reads data from the cache. The issue stems from the use of Python pickle, which is susceptible to insecure deserialization.
Recommendations Versions prior to 5.6.4 should be updated.

Exploit

Fix

RCE

Code Injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69872
GHSA-W8V5-VHQR-4H9V
PYSEC-2026-2447

Affected Products

Diskcache