CVE-2025-67748(trailofbits / fickling)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-184CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fickling

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Products
fickling

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 HIGH: CVE-2025-67748 (CVSS 7.8) - Fickling Python pickle analyzer bypass. Versions <0.1.6 incorrectly flag unsafe pickles as LIKELY_SAFE due to missing pty module check. Update to 0.1.6 immediately. #CVE #Vulnerability #PatchNow https://t.co/IosLTmCkll

    0000025
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptrailofbitsfickling---

Explore more