CVE-2026-22609 describes a critical vulnerability in Fickling, a Python pickling decompiler and static analyzer, specifically affecting versions prior to 0.1.7. The flaw lies in its static analyzer's unsafe_imports() method, which fails to identify several high-risk Python modules that can facilitate arbitrary code execution. This oversight allows malicious pickles to bypass Fickling's primary safety checks, as they are not flagged as unsafe. Rated with a CVSS score of 7.8 (High), this vulnerability has an attack vector of Local (AV:L) and low attack complexity (AC:L), requiring user interaction (UI:R). A successful exploit could lead to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability is categorized under CWE-184 (Incomplete List of Disallowed Inputs) and CWE-502 (Deserialization of Untrusted Data). Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, with zero mentions across social media and news articles, which is typical for a significant percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.7CPE matchmatch criteria | cpe:2.3:a:trailofbits:fickling:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.