Executive brief
Fickling is a security tool used to analyze and detect malicious Python pickle files. A vulnerability was found where specially crafted malicious files could bypass Fickling's safety checks, leading the tool to incorrectly label them as safe. If a user then opens such a file based on this false assurance, an attacker could execute arbitrary code on the user's system.
Technical details
Fickling is vulnerable to a detection bypass that allows arbitrary code execution via unsafe deserialization. The issue stems from two root causes: the 'pty' module was missing from the blocklist of unsafe imports, and the 'unused variable' heuristic could be subverted. An attacker can bypass the heuristic by using the 'BUILD' opcode to 'use' a variable that would otherwise be left on the stack after a malicious operation (like REDUCE or INST). This causes Fickling to incorrectly categorize the file as 'LIKELY_SAFE'. The vulnerability is addressed in version 0.1.6 by updating the blocklist and improving detection logic.
Affected products
- trailofbits fickling < 0.1.6
Timeline
- 2025-12-15: disclosed
- 2025-12-15: advisory
- 2025-12-15: patched: Fixed in version 0.1.6