criticalCVSS 9.8Vulnerability
GHSA-rmpp-8wf5-xx5q
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-m273-6v24-x4m4. This link is maintained to preserve external references. ### Original Description picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution.
Properties
- ghsa_id
- GHSA-rmpp-8wf5-xx5q
- severity
- critical
- summary
- Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
- cvss_score
- 9.8
- cve_id
- GHSA-rmpp-8wf5-xx5q
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-06-17T18:35:56Z
- source_url
- https://github.com/advisories/GHSA-rmpp-8wf5-xx5q
- ghsa_updated
- 2026-06-18T14:44:11Z
Related Entities (4)
AFFECTS (1)
→[Software]pip/picklescan
HAS_WEAKNESS (1)
→[Weakness]Deserialization of Untrusted Data
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]pip/picklescan
Explore deeper with Ninja Signal's threat intelligence graph