CVE-2025-67747 describes a critical vulnerability in Fickling, a Python pickling decompiler and static analyzer, affecting versions prior to 0.1.6. The flaw stems from Fickling's failure to block unsafe imports of 'marshal' and 'types' modules, allowing attackers to craft malicious pickle files that bypass Fickling's security checks. This enables arbitrary code execution on a user's system upon deserialization of such a file, posing a significant risk to any system relying on Fickling for pickle file vetting. The vulnerability carries a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction, and leading to high impacts on confidentiality, integrity, and availability. Its FAUCET Risk Score is 86/100, highlighting its severity. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE. The issue was addressed in Fickling version 0.1.6.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.6CPE matchmatch criteria | cpe:2.3:a:trailofbits:fickling:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.