CVE-2026-30108Disclosure

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-21: 2Technical Details · 2026-04-21: 204-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Geng Yang@geng_zast
    Disclosure

    http://ZAST.AI verified an insecure deserialization bug in pycel <= 1.0b30. @DirkGor It is now tracked as CVE-2026-30108. The payload executed during pickle.load() before the object was rejected. pycel has 618 GitHub stars so far. https://t.co/WqAbLKo6Bi

    Post summary

    An insecure deserialization vulnerability (CVE-2026-30108) in pycel ≤1.0b30 has been verified; the payload executes during pickle.load() before rejection, and the issue is now tracked.

    1001063
    47 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    ZAST verified an insecure deserialization issue in pycel <= 1.0b30. @DirkGor The issue now carries CVE-2026-30108. ExcelCompiler.from_file() passed pickle-backed input into pickle.load(). Project footprint: 618 GitHub stars so far. https://t.co/hgbqR0fO7l

    Post summary

    The tweet announces CVE-2026-30108, an insecure deserialization vulnerability in pycel, describing how ExcelCompiler.from_file() mishandles pickle data.

    1000038
    33 followersView on X

Explore more