CVE-2025-69872Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-11: 1Mentions · 2026-02-12: 2Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 2Technical Details · 2026-03-24: 102-1102-1203-24
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-122
Disclosure2
2026-03-241
Patch1
Full discourse4 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2025-69872: Cache Me if You Can: Unpickling RCE in Python DiskCache A critical insecure deserialization vulnerability in the popular python-diskcache library allows local attackers to achieve arbitrary code execution. By manipulating the underlyin... https://cvereports.com/reports/CVE-2025-69872

    Post summary

    The report discloses a critical insecure deserialization flaw in python‑diskcache that can lead to local arbitrary code execution, but no PoC, exploit code, active attacks, or patch information is provided.

    0000138
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69872 Python-Diskcache Arbitrary Code Execution via Malicious Pickle Serialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69872

    Post summary

    The entry announces CVE‑2025‑69872, describing an arbitrary code execution flaw in Python‑Diskcache caused by malicious pickle deserialization, but does not mention exploit availability, active use, or remediation.

    0001034
    4.0K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora 43 and 44 ship python-diskcache flaw CVE-2025-69872 allowing arbitrary code execution via pickle - users must update to 5.6.4-12 with dnf immediately. https://threatcluster.io/cluster/critical-security-flaw-in-python-diskcache-affects-fedora-us-1d8ed56e

    Post summary

    The post announces a critical CVE‑2025‑69872 in python‑diskcache for Fedora 43/44, highlights the RCE risk, and urges users to apply the 5.6.4‑12 update immediately.

    00000133
    113 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-69872 - Critical DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when ... https://www.thehackerwire.com/vulnerability/CVE-2025-69872/ https://t.co/zl3yLwX1Rz

    Post summary

    The tweet announces CVE‑2025‑69872, a critical flaw in python‑diskcache allowing arbitrary code execution via default pickle serialization, with no mention of exploits, patches, or active attacks.

    0000058
    112 followersView on X

Explore more