CVE-2025-67748

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.
Configurations

Configuration 1 (hide)

cpe:2.3:a:trailofbits:fickling:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-16 01:15

Updated : 2026-01-02 15:58


NVD link : CVE-2025-67748

Mitre link : CVE-2025-67748

CVE.ORG link : CVE-2025-67748


JSON object : View

Products Affected

trailofbits

  • fickling
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-184

Incomplete List of Disallowed Inputs

CWE-502

Deserialization of Untrusted Data