CVE-2026-56315General

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attackers can craft malicious pickle files importing these unblocked modules to achieve remote code execution while bypassing picklescan's safety validation entirely.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-06-23); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-23: 2Mentions · 2026-06-27: 1Mentions · 2026-07-17: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-23: 2Technical Details · 2026-06-27: 1Technical Details · 2026-07-17: 106-2306-2707-17
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-232
Disclosure1General1
2026-06-271
Patch1
2026-07-171
General1
Full discourse4 posts
  • SecAlerts@SecAlertsCo
    Patch

    🥒 picklescan, the tool meant to catch malicious pickle files, has an RCE bypass. CVE-2026-56315: 7+ stdlib modules (uuid, imaplib, more) go unblocked, letting attackers sneak through. Update to 1.0.4. #Python #AppSec https://secalerts.co/vulnerability/CVE-2026-56315?utm_campaign=x https://t.co/cgkw2USEnN

    Post summary

    The tweet reports an RCE bypass in picklescan (CVE-2026-56315) affecting several stdlib modules and recommends updating to version 1.0.4 to remediate.

    11010133
    845 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-56315: picklescan Python Library Deserialization Flaw - What It Means for Your Business and How to Respond https://hubs.ly/Q04pWcnb0

    Post summary

    The text indicates a CVE involving a picklescan Python library deserialization flaw, but offers no proof‑of‑concept, exploitation details, or patch information.

    0000037
    32 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - picklescan Blocklist Bypass → Remote Code Execution (CVE-2026-56315) picklescan before 1.0.4 fails to block at least seven Python standard-library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib), exposing eight functions that grant direct command execution. A crafted malicious pickle importing these modules runs arbitrary code while passing picklescan's safety validation entirely (CVSS 9.3). 👉 Affected: picklescan (PyPI) < 1.0.4 | Upgrade to 1.0.4

    Post summary

    The advisory reveals that picklescan versions before 1.0.4 allow remote code execution through a blocklist bypass and recommends upgrading to 1.0.4.

    0000083
    226 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-56315 Remote Code Execution in Picklescan Before 1.0.4 via Unbl... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56315 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE‑2026‑56315, noting a RCE flaw in Picklescan prior to 1.0.4, but offers no PoC, exploit, or patch details.

    00000101
    4.1K followersView on X

Explore more