CVE-2025-56005

Source
https://cve.org/CVERecord?id=CVE-2025-56005
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-56005.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-56005
Downstream
Related
Published
2026-01-20T00:00:00Z
Modified
2026-07-21T03:41:47.146127910Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the picklefile parameter in the yacc() function. This parameter accepts a .pkl file that is deserialized with pickle.load() without validation. Because pickle allows execution of embedded code via __reduce__(), an attacker can achieve code execution by passing a malicious pickle file. The parameter is not mentioned in official documentation or the GitHub repository, yet it is active in the PyPI version. This introduces a stealthy backdoor and persistence risk. NOTE: A third-party states that this vulnerability should be rejected because the proof of concept does not demonstrate arbitrary code execution and fails to complete successfully.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/56xxx/CVE-2025-56005.json",
    "cna_assigner": "mitre",
    "isDisputed": true
}
References

Affected packages

Git / github.com/dabeaz/ply

Affected ranges

Type
GIT
Repo
https://github.com/dabeaz/ply
Events
Database specific
{
    "cpe": "cpe:2.3:a:dabeaz:ply:3.11:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "3.11"
        },
        {
            "last_affected": "3.11"
        }
    ]
}

Affected versions

3.*
3.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-56005.json"