Unsafe Deserialization Vulnerability in Picklescan by Mmaitre314
CVE-2026-53874

9.3CRITICAL

Key Information:

Vendor

Picklescan

Vendor
CVE Published:
17 June 2026

What is CVE-2026-53874?

The Picklescan library prior to version 1.0.1 is vulnerable to an unsafe deserialization flaw that permits unauthenticated adversaries to execute arbitrary code. This vulnerability arises when malicious code is embedded in pickle files that can evade detection, yet become executable when the affected library processes these pickle files from untrusted origins. This scenario is particularly concerning as it exploits nested eval calls hidden within callable objects, enabling attackers to execute harmful actions remotely without requiring user authentication.

Affected Version(s)

picklescan 0 < 1.0.1

picklescan 1.0.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ogrisel
.