Unsafe Pickle Deserialization in Picklescan by Maitre317
CVE-2026-53872

8.7HIGH

Key Information:

Vendor

Picklescan

Vendor
CVE Published:
17 June 2026

What is CVE-2026-53872?

Picklescan prior to version 0.0.35 suffers from an unsafe pickle deserialization vulnerability. This flaw enables unauthenticated attackers to exploit the system by chaining io.FileIO and urllib.request.urlopen, leading to unauthorized access to sensitive server files. Attackers can potentially exfiltrate critical data, such as /etc/passwd, to external servers, thereby compromising server security.

Affected Version(s)

picklescan 0 < 0.0.35

picklescan 0.0.35

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

shivasurya
.