Junglewise Threat Intelligence

CVE-2026-53872: picklescan unsafe pickle deserialization arbitrary file read

CVE-2026-53872 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: picklescan (PyPI). Vendors: PyPI.

Executive brief

Picklescan is a security tool designed to scan Python pickle files for malicious code. A vulnerability in versions prior to 0.0.35 allows an attacker to bypass security filters and read sensitive files from the server where the tool is running. This could lead to the theft of system configuration files or credentials, potentially allowing further access to the organization's infrastructure.

Technical details

A deserialization vulnerability exists in picklescan versions prior to 0.0.35 due to unsafe handling of Python pickle data. While the tool attempts to block common Remote Code Execution (RCE) keywords like 'os' or 'exec', it fails to restrict other dangerous standard library components. An attacker can chain 'io.FileIO' to open local files and 'urllib.request.urlopen' to exfiltrate the file contents via an HTTP POST request. This bypasses RCE-focused blocklists to achieve arbitrary file read and Server-Side Request Forgery (SSRF). The issue is resolved in version 0.0.35.

Affected products

  • picklescan picklescan < 0.0.35

Timeline

  • 2026-01-07: advisory: GitHub Security Advisory published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats