
http://ZAST.AI verified an insecure deserialization bug in pycel <= 1.0b30. @DirkGor It is now tracked as CVE-2026-30108. The payload executed during pickle.load() before the object was rejected. pycel has 618 GitHub stars so far. https://t.co/WqAbLKo6Bi
Post summary
An insecure deserialization vulnerability (CVE-2026-30108) in pycel ≤1.0b30 has been verified; the payload executes during pickle.load() before rejection, and the issue is now tracked.

