CVE-2025-67747(trailofbits / fickling)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` from the block list of unsafe module imports. Fickling started blocking both modules to address this issue. This allows an attacker to craft a malicious pickle file that can bypass fickling since it misses detections for `types.FunctionType` and `marshal.loads`. A user who deserializes such a file, believing it to be safe, would inadvertently execute arbitrary code on their system. This impacts any user or system that uses Fickling to vet pickle files for security issues. The issue was fixed in version 0.1.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fickling

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Products
fickling

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 HIGH SEVERITY: CVE-2025-67747 (CVSS 7.8) Fickling Python pickle analyzer <0.1.6 fails to block marshal & types modules, allowing attackers to bypass security checks & execute arbitrary code. Patch to v0.1.6 immediately. #CVE #Vulnerability #PatchNow https://t.co/PCCirjvfiD

    0000018
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptrailofbitsfickling---

Explore more