
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22608 is a security scanner bypass vulnerability in Fickling, a Python pickling decompiler and static analyzer developed by Trail of Bits. The flaw exists in versions prior to 0.1.6 (inclusive), where the ctypes and pydoc Python modules are not explicitly blocked in Fickling's unsafe imports list. By chaining these two modules together, an attacker can craft a malicious pickle file that achieves remote code execution (RCE) while Fickling's scanner still reports the file as LIKELY_SAFE. The vulnerability was disclosed on January 9, 2026, and patched in version 0.1.7. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory).
The root cause is an incomplete blocklist of dangerous Python modules in Fickling's unsafe_imports detection logic (CWE-184: Incomplete List of Disallowed Inputs; CWE-502: Deserialization of Untrusted Data). An attacker crafts a pickle payload that uses pydoc.locate — which was not blocked — to dynamically resolve ctypes.windll.kernel32.WinExec (or equivalent OS-level functions), then calls the resolved function with a malicious argument. Because pydoc was not on the blocklist, Fickling's static analysis passes the file as safe. The exploit also uses a benign builtins.Exception object to absorb the unused variable result, further evading heuristic checks. A public proof-of-concept payload was included in the original advisory (GitHub Advisory, Patch Commit).
Successful exploitation allows an attacker to execute arbitrary code on the system of any user or automated pipeline that loads the malicious pickle file, with full confidentiality, integrity, and availability impact. The attack is particularly dangerous in AI/ML pipelines where pickle files (e.g., PyTorch model weights) are routinely loaded from untrusted sources, and Fickling is used as a security gate. Because the scanner reports the file as safe, defenders relying solely on Fickling would have no indication of compromise. The vulnerability also affects other pickle scanning tools such as picklescan, which similarly do not block pydoc.locate (GitHub Advisory).
A detailed proof-of-concept payload was publicly disclosed as part of the GitHub Security Advisory at the time of disclosure on January 9, 2026, making exploitation straightforward for any attacker with access to the PoC (GitHub Advisory). Exploitation requires user interaction — a victim must load the malicious pickle file — and the attack vector is local per CVSS v3.1 scoring. The EPSS score is approximately 0.076%, indicating low current exploitation probability. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
stealth_ctypes.pkl) that uses the GLOBAL opcode to import pydoc.locate, then calls locate('ctypes.windll.kernel32.WinExec') to resolve the Windows API function dynamically.builtins.Exception object's __setstate__ dict (e.g., {'rce_status': result}), preventing Fickling's unused-variable heuristic from flagging the payload.picklescan; both tools will report the file as LIKELY_SAFE due to the missing blocklist entries for pydoc and ctypes..pkl file through a model repository, file share, or supply chain vector targeting users or automated ML pipelines that use Fickling for safety validation.pickle.load() or torch.load()), the Pickle VM executes the embedded opcodes, calling WinExec('calc.exe', 1) (or any attacker-chosen command) on the victim's system (GitHub Advisory)..pkl files containing pydoc or ctypes module references when decompiled; files that pass Fickling ≤ 0.1.6 safety checks but contain GLOBAL pydoc locate or GLOBAL ctypes opcodes.calc.exe, cmd.exe, bash, or other OS commands); unusual ctypes-based DLL loads from within a Python process.LIKELY_SAFE by Fickling, followed by unexpected system calls or network activity.Upgrade Fickling to version 0.1.7 or later immediately; this release adds ctypes and pydoc to the list of unsafe imports and also checks all components of dotted module paths against the blocklist (GitHub Advisory, Patch Commit). Do not rely solely on Fickling or picklescan as the only security control for untrusted pickle files; implement defense-in-depth by sandboxing pickle deserialization in isolated environments. Avoid loading pickle files from untrusted or unverified sources, particularly in AI/ML pipelines where model weights are fetched from public repositories.
The vulnerability was reported by security researcher 0x-Apollyon and addressed by Trail of Bits maintainer thomas-chauchefoin-tob in a batch fix (PR #195) that resolved five separate security advisories simultaneously (GitHub PR #195). The advisory noted that even competing tools like picklescan share the same blind spot for pydoc.locate, highlighting a broader gap in the pickle security scanning ecosystem. Coverage was picked up by several vulnerability aggregators and security news outlets shortly after disclosure (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."