CVE-2026-22606: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22606 is a security bypass vulnerability in Trail of Bits' fickling, a Python library used to detect malicious pickle files. The flaw allows crafted pickle files using runpy.run_path() or runpy.run_module() to evade fickling's safety checks, resulting in arbitrary code execution when the file is deserialized. It affects fickling versions up to and including 0.1.6, with the fix introduced in version 0.1.7. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.9 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is an incomplete blocklist in fickling's UnsafeImports analysis class within fickling/analysis.py (CWE-184), which fails to include the runpy module and its functions (run_path, run_module, _run_code, _run_module_code) as unsafe imports (CWE-502). Because runpy is not blocklisted, a pickle file invoking runpy.run_path() or runpy.run_module() in its __reduce__ method only triggers fickling's weaker UnusedVariables heuristic, resulting in a SUSPICIOUS classification rather than OVERTLY_MALICIOUS. This is the same root cause pattern as related CVEs for pty (CVE-2025-67748) and marshal/types (CVE-2025-67747). The fix was applied in commit 9a2b3f8 by adding runpy to the unsafe imports blocklist (GitHub Advisory).

Impact

Successful exploitation allows an attacker to achieve arbitrary code execution with full confidentiality, integrity, and availability impact on the victim's system. The attack is particularly insidious because fickling is specifically deployed as a security control to prevent exactly this class of attack — its misclassification of malicious pickles as merely SUSPICIOUS rather than OVERTLY_MALICIOUS causes downstream pipelines to permit loading of attacker-controlled files. This is especially dangerous in ML model repository workflows where untrusted pickle files (e.g., serialized PyTorch models) are routinely scanned before loading (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, demonstrating the full attack chain from crafting the malicious pickle to confirming code execution (GitHub Advisory). The EPSS score is approximately 0.068%, indicating low current exploitation probability. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT (Feedly).

Exploitation steps

  1. Craft malicious pickle: Create a Python script that serializes a malicious payload using runpy.run_path() or runpy.run_module() in the __reduce__ method:
import pickle, runpy
class MaliciousPayload:
    def __reduce__(self):
        return (runpy.run_path, ("/tmp/malicious_script.py",))
with open("malicious.pkl", "wb") as f:
    pickle.dump(MaliciousPayload(), f)
  1. Prepare payload script: Create the script to be executed on the victim's system (e.g., /tmp/malicious_script.py) containing arbitrary commands such as reverse shell code or data exfiltration logic.
  2. Upload to target pipeline: Submit the crafted malicious.pkl to a model repository or pipeline that uses fickling (versions ≤ 0.1.6) as a security gate.
  3. Bypass security check: Fickling scans the file and returns SUSPICIOUS severity (not OVERTLY_MALICIOUS), so the pipeline's rejection logic does not trigger and the file is permitted.
  4. Trigger code execution: When the victim's system loads the pickle file (e.g., via pickle.load()), runpy.run_path() executes the attacker's script, achieving arbitrary code execution on the victim's machine (GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected .pkl files referencing runpy module in pickle disassembly; unexpected files created by the deserialization process (e.g., /tmp/pwned or similar attacker-created artifacts); new scripts dropped in world-writable directories like /tmp/.
  • Logs: Fickling scan output showing SUSPICIOUS severity for pickle files that invoke runpy.run_path or runpy.run_module — these should be treated as potentially malicious in unpatched environments; pipeline logs showing files classified as SUSPICIOUS being permitted through security gates.
  • Process: Unexpected child processes spawned by the Python interpreter during model loading (e.g., shell commands, network utilities); Python processes executing scripts from /tmp/ or other unusual paths.
  • Network: Outbound connections from model-loading processes to unknown external IPs, potentially indicating reverse shell or data exfiltration activity following pickle deserialization (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade fickling to version 0.1.7 or later, which adds runpy and its submodules to the unsafe imports blocklist via commit 9a2b3f8 (GitHub Advisory). As a defense-in-depth measure, organizations should not rely solely on fickling as a single security gate — implement multiple independent controls for validating pickle files from untrusted sources. Additionally, restrict code execution privileges for processes that load ML models, and avoid deserializing pickle files from untrusted or unverified sources regardless of scan results (Feedly).

Community reactions

Trail of Bits (the maintainer of fickling) published the security advisory on January 9, 2026, and promptly patched the issue in version 0.1.7. The vulnerability was noted in the context of a broader pattern of blocklist bypasses in fickling, with the maintainer acknowledging the same root cause as prior CVEs for pty, marshal, and types modules. Community discussion was observed on Bluesky and security aggregator sites shortly after disclosure (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management