highCVSS 8.8Vulnerability

GHSA-5gp7-4733-2w2v

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-hgrh-qx5j-jfwx. This link is maintained to preserve external references. ## Original Description PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to bypass security checks. Malicious actors can craft pickle payloads using pty.spawn to achieve arbitrary code execution when files are processed by PickleScan.

Properties

ghsa_id
GHSA-5gp7-4733-2w2v
summary
Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn
severity
high
cvss_score
8.8
cve_id
GHSA-5gp7-4733-2w2v
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-06-17T18:35:56Z
source_url
https://github.com/advisories/GHSA-5gp7-4733-2w2v
ghsa_updated
2026-06-18T14:41:21Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/picklescan

AFFECTS (1)

[Software]pip/picklescan

HAS_WEAKNESS (1)

[Weakness]Protection Mechanism Failure

Explore deeper with Ninja Signal's threat intelligence graph