criticalCVSS 10Vulnerability

GHSA-82fg-2r99-h7v6

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-vvpj-8cmc-gx39. This link is maintained to preserve external references. ### Original Description picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.system, builtins.exec, or subprocess.call to achieve remote code execution.

Properties

ghsa_id
GHSA-82fg-2r99-h7v6
severity
critical
summary
Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
cvss_score
10
cve_id
GHSA-82fg-2r99-h7v6
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-06-17T18:35:57Z
source_url
https://github.com/advisories/GHSA-82fg-2r99-h7v6
ghsa_updated
2026-06-18T14:45:21Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/picklescan

AFFECTS (1)

[Software]pip/picklescan

HAS_WEAKNESS (1)

[Weakness]Permissive List of Allowed Inputs

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-82fg-2r99-h7v6 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal