Junglewise Threat Intelligence

mmaitre314 picklescan arbitrary file creation via unsafe deserialization

Severity: medium · CVSS 5.5 · Published 2026-02-02

Technologies: picklescan (PyPI). Vendors: PyPI.

Executive brief

Picklescan, a tool used to scan Python pickle files for malicious code, is itself vulnerable to a flaw that allows attackers to create empty files on a server. By providing a specially crafted file for scanning, an unauthenticated attacker can create "lock files" or other markers that could crash the application or prevent it from starting. While this cannot be used to steal data or modify existing files, it can disrupt business operations and service availability.

Technical details

A deserialization vulnerability (CWE-502) exists in picklescan due to the unsafe processing of untrusted pickle data. An attacker can bypass RCE-focused blocklists by using a 'gadget chain' involving the standard library's logging.FileHandler class. When deserialized, this class can be instantiated to create a zero-byte file at an arbitrary path if the file does not already exist. While it does not allow overwriting existing data, it can be used for filesystem pollution or to create lock files that trigger a Denial of Service (DoS). The vulnerability is addressed in version 1.0.1.

Affected products

  • mmaitre314 picklescan < 1.0.1

Timeline

  • 2026-02-02: disclosed
  • 2026-02-02: advisory
  • 2026-02-02: patched: Fixed in version 1.0.1

References

Related threats