criticalCVSS 9.8Vulnerability

GHSA-rmpp-8wf5-xx5q

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-m273-6v24-x4m4. This link is maintained to preserve external references. ### Original Description picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution.

Properties

ghsa_id
GHSA-rmpp-8wf5-xx5q
severity
critical
summary
Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
cvss_score
9.8
cve_id
GHSA-rmpp-8wf5-xx5q
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-06-17T18:35:56Z
source_url
https://github.com/advisories/GHSA-rmpp-8wf5-xx5q
ghsa_updated
2026-06-18T14:44:11Z

Related Entities (4)

AFFECTS (1)

[Software]pip/picklescan

HAS_WEAKNESS (1)

[Weakness]Deserialization of Untrusted Data

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/picklescan

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-rmpp-8wf5-xx5q (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal