
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22606 is a security bypass vulnerability in Trail of Bits' fickling, a Python library used to detect malicious pickle files. The flaw allows crafted pickle files using runpy.run_path() or runpy.run_module() to evade fickling's safety checks, resulting in arbitrary code execution when the file is deserialized. It affects fickling versions up to and including 0.1.6, with the fix introduced in version 0.1.7. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.9 (High) (GitHub Advisory, Feedly).
The root cause is an incomplete blocklist in fickling's UnsafeImports analysis class within fickling/analysis.py (CWE-184), which fails to include the runpy module and its functions (run_path, run_module, _run_code, _run_module_code) as unsafe imports (CWE-502). Because runpy is not blocklisted, a pickle file invoking runpy.run_path() or runpy.run_module() in its __reduce__ method only triggers fickling's weaker UnusedVariables heuristic, resulting in a SUSPICIOUS classification rather than OVERTLY_MALICIOUS. This is the same root cause pattern as related CVEs for pty (CVE-2025-67748) and marshal/types (CVE-2025-67747). The fix was applied in commit 9a2b3f8 by adding runpy to the unsafe imports blocklist (GitHub Advisory).
Successful exploitation allows an attacker to achieve arbitrary code execution with full confidentiality, integrity, and availability impact on the victim's system. The attack is particularly insidious because fickling is specifically deployed as a security control to prevent exactly this class of attack — its misclassification of malicious pickles as merely SUSPICIOUS rather than OVERTLY_MALICIOUS causes downstream pipelines to permit loading of attacker-controlled files. This is especially dangerous in ML model repository workflows where untrusted pickle files (e.g., serialized PyTorch models) are routinely scanned before loading (GitHub Advisory, Feedly).
A proof-of-concept exploit is publicly available in the GitHub security advisory, demonstrating the full attack chain from crafting the malicious pickle to confirming code execution (GitHub Advisory). The EPSS score is approximately 0.068%, indicating low current exploitation probability. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT (Feedly).
runpy.run_path() or runpy.run_module() in the __reduce__ method:import pickle, runpy
class MaliciousPayload:
def __reduce__(self):
return (runpy.run_path, ("/tmp/malicious_script.py",))
with open("malicious.pkl", "wb") as f:
pickle.dump(MaliciousPayload(), f)/tmp/malicious_script.py) containing arbitrary commands such as reverse shell code or data exfiltration logic.malicious.pkl to a model repository or pipeline that uses fickling (versions ≤ 0.1.6) as a security gate.SUSPICIOUS severity (not OVERTLY_MALICIOUS), so the pipeline's rejection logic does not trigger and the file is permitted.pickle.load()), runpy.run_path() executes the attacker's script, achieving arbitrary code execution on the victim's machine (GitHub Advisory)..pkl files referencing runpy module in pickle disassembly; unexpected files created by the deserialization process (e.g., /tmp/pwned or similar attacker-created artifacts); new scripts dropped in world-writable directories like /tmp/.SUSPICIOUS severity for pickle files that invoke runpy.run_path or runpy.run_module — these should be treated as potentially malicious in unpatched environments; pipeline logs showing files classified as SUSPICIOUS being permitted through security gates./tmp/ or other unusual paths.The primary remediation is to upgrade fickling to version 0.1.7 or later, which adds runpy and its submodules to the unsafe imports blocklist via commit 9a2b3f8 (GitHub Advisory). As a defense-in-depth measure, organizations should not rely solely on fickling as a single security gate — implement multiple independent controls for validating pickle files from untrusted sources. Additionally, restrict code execution privileges for processes that load ML models, and avoid deserializing pickle files from untrusted or unverified sources regardless of scan results (Feedly).
Trail of Bits (the maintainer of fickling) published the security advisory on January 9, 2026, and promptly patched the issue in version 0.1.7. The vulnerability was noted in the context of a broader pattern of blocklist bypasses in fickling, with the maintainer acknowledging the same root cause as prior CVEs for pty, marshal, and types modules. Community discussion was observed on Bluesky and security aggregator sites shortly after disclosure (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."