Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1370
  • PyPI/fickling
Fickling vulnerable to detection bypass due to "builtins" blindness 07 Jul
  • Fix available
  • Severity - 8.9 (High)
PYSEC-2026-1372
  • PyPI/fickling
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist 07 Jul
  • Fix available
  • Severity - 8.9 (High)
PYSEC-2026-1369
  • PyPI/fickling
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection 07 Jul
  • Fix available
  • Severity - 8.9 (High)
PYSEC-2026-1371
  • PyPI/fickling
Fickling Blocklist Bypass: cProfile.run() 07 Jul
  • Fix available
  • Severity - 8.9 (High)
PYSEC-2026-1373
  • PyPI/fickling
Fickling has a bypass via runpy.run_path() and runpy.run_module() 07 Jul
  • Fix available
  • Severity - 8.9 (High)
PYSEC-2026-1368
  • PyPI/fickling
Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list 07 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2150
  • PyPI/fickling
See record for full details 04 Jul
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-2149
  • PyPI/fickling
See record for full details 04 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-5cxw-w2xg-2m8h
  • PyPI/fickling
fickling's `platform` module subprocess invocation evades `check_safety()` with `LIKELY_SAFE` 13 Mar
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-r48f-3986-4f9c
  • PyPI/fickling
fickling modules linecache, difflib and gc are missing from the unsafe modules blocklist 13 Mar
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-5hwf-rc88-82xm
  • PyPI/fickling
Fickling missing RCE-capable modules in UNSAFE_IMPORTS 04 Mar
  • Fix available
  • Severity - 8.9 (High)
GHSA-wccx-j62j-r448
  • PyPI/fickling
Fickling has `always_check_safety()` bypass: pickle.loads and _pickle.loads remain unhooked 04 Mar
  • Fix available
  • Severity - 8.9 (High)
GHSA-mhc9-48gj-9gp3
  • PyPI/fickling
Fickling has safety check bypass via REDUCE+BUILD opcode sequence 25 Feb
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-mxhj-88fx-4pcv
  • PyPI/fickling
Fickling: OBJ opcode call invisibility bypasses all safety checks 24 Feb
  • Fix available
  • Severity - 8.6 (High)
GHSA-83pf-v6qq-pwmr
  • PyPI/fickling
Fickling has a detection bypass via stdlib network-protocol constructors 20 Feb
  • Fix available
  • Severity - 2.3 (Low)
GHSA-h4rm-mm56-xf63
  • PyPI/fickling
Fickling vulnerable to detection bypass due to "builtins" blindness 09 Jan
  • Fix available
  • Severity - 8.9 (High)