{"id":"PYSEC-2025-113","details":"Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.","aliases":["CVE-2025-67748","GHSA-r7v6-mfhq-g3m2"],"modified":"2026-05-20T09:19:00.310433Z","published":"2025-12-16T01:15:52.950Z","references":[{"type":"FIX","url":"https://github.com/trailofbits/fickling/pull/108"},{"type":"FIX","url":"https://github.com/trailofbits/fickling/pull/187"},{"type":"EVIDENCE","url":"https://github.com/trailofbits/fickling/security/advisories/GHSA-r7v6-mfhq-g3m2"}],"affected":[{"package":{"name":"fickling","ecosystem":"PyPI","purl":"pkg:pypi/fickling"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.6"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.1.2","0.1.3","0.1.4","0.1.5"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/fickling/PYSEC-2025-113.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}