CVE-2026-53874 PUBLISHED

picklescan - Arbitrary Code Execution via Obfuscated eval Call

Assigner: VulnCheck
Reserved: 10.06.2026 Published: 17.06.2026 Updated: 17.06.2026

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle files that evades detection but executes when the pickle is loaded from untrusted sources.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor picklescan
Product picklescan
Versions Default: unaffected
  • affected from 0 to 1.0.1 (excl.)
  • Version 1.0.1 is unaffected

Credits

  • ogrisel reporter

References

Problem Types

  • Deserialization of Untrusted Data CWE