VYPR
High severity7.8OSV Advisory· Published Jan 10, 2026· Updated Jun 17, 2026

CVE-2026-22607

CVE-2026-22607

Description

Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat Python's cProfile module as unsafe. Because of this, a malicious pickle that uses cProfile.run() is classified as SUSPICIOUS instead of OVERTLY_MALICIOUS. If a user relies on Fickling's output to decide whether a pickle is safe to deserialize, this misclassification can lead them to execute attacker-controlled code on their system. This affects any workflow or product that uses Fickling as a security gate for pickle deserialization. This issue has been patched in version 0.1.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ficklingPyPI
< 0.1.70.1.7

Affected products

3
  • Trailofbits/FicklingOSV2 versions
    master, v0.0.1, v0.0.2, …+ 1 more
    • (no CPE)range: master, v0.0.1, v0.0.2, …
    • cpe:2.3:a:trailofbits:fickling:*:*:*:*:*:*:*:*range: <0.1.7
  • ghsa-coords
    Range: < 0.1.7

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.