HIGH 8.1 PyPI

Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx

GHSA-fcqg-3mwf-cfcf

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-9w88-8rmg-7g2p. This link is maintained to preserve external references.

Original Description

picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load().

Ready to move

Start Securing

Free, no credit card | First findings in minutes