High severityNVD Advisory· Published Jun 17, 2026· Updated Jun 17, 2026
picklescan - Arbitrary File Read via Unsafe Pickle Deserialization
CVE-2026-53872
Description
picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read arbitrary server files by chaining io.FileIO and urllib.request.urlopen. Attackers can bypass RCE-focused blocklists to exfiltrate sensitive data like /etc/passwd to external servers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
picklescanPyPI | < 0.0.35 | 0.0.35 |
Affected products
1- Range: <0.0.35
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-9726-w42j-3qjrghsaADVISORY
- github.com/mmaitre314/picklescan/security/advisories/GHSA-9726-w42j-3qjrghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-53872ghsaADVISORY
- www.vulncheck.com/advisories/picklescan-arbitrary-file-read-via-unsafe-pickle-deserializationghsathird-party-advisoryWEB
- github.com/mmaitre314/picklescan/commit/a01c58d5dd7960db557b849817c0ab83ab111ef1ghsaWEB
- github.com/mmaitre314/picklescan/pull/55ghsaWEB
- github.com/mmaitre314/picklescan/releases/tag/v0.0.35ghsaWEB
News mentions
0No linked articles in our index yet.