CVE-2026-22608: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22608 is a security scanner bypass vulnerability in Fickling, a Python pickling decompiler and static analyzer developed by Trail of Bits. The flaw exists in versions prior to 0.1.6 (inclusive), where the ctypes and pydoc Python modules are not explicitly blocked in Fickling's unsafe imports list. By chaining these two modules together, an attacker can craft a malicious pickle file that achieves remote code execution (RCE) while Fickling's scanner still reports the file as LIKELY_SAFE. The vulnerability was disclosed on January 9, 2026, and patched in version 0.1.7. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory).

Technical details

The root cause is an incomplete blocklist of dangerous Python modules in Fickling's unsafe_imports detection logic (CWE-184: Incomplete List of Disallowed Inputs; CWE-502: Deserialization of Untrusted Data). An attacker crafts a pickle payload that uses pydoc.locate — which was not blocked — to dynamically resolve ctypes.windll.kernel32.WinExec (or equivalent OS-level functions), then calls the resolved function with a malicious argument. Because pydoc was not on the blocklist, Fickling's static analysis passes the file as safe. The exploit also uses a benign builtins.Exception object to absorb the unused variable result, further evading heuristic checks. A public proof-of-concept payload was included in the original advisory (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to execute arbitrary code on the system of any user or automated pipeline that loads the malicious pickle file, with full confidentiality, integrity, and availability impact. The attack is particularly dangerous in AI/ML pipelines where pickle files (e.g., PyTorch model weights) are routinely loaded from untrusted sources, and Fickling is used as a security gate. Because the scanner reports the file as safe, defenders relying solely on Fickling would have no indication of compromise. The vulnerability also affects other pickle scanning tools such as picklescan, which similarly do not block pydoc.locate (GitHub Advisory).

Exploitability

A detailed proof-of-concept payload was publicly disclosed as part of the GitHub Security Advisory at the time of disclosure on January 9, 2026, making exploitation straightforward for any attacker with access to the PoC (GitHub Advisory). Exploitation requires user interaction — a victim must load the malicious pickle file — and the attack vector is local per CVSS v3.1 scoring. The EPSS score is approximately 0.076%, indicating low current exploitation probability. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Craft the malicious pickle payload: Using the public PoC, generate a pickle file (stealth_ctypes.pkl) that uses the GLOBAL opcode to import pydoc.locate, then calls locate('ctypes.windll.kernel32.WinExec') to resolve the Windows API function dynamically.
  2. Evade unused-variable detection: Store the execution result in a builtins.Exception object's __setstate__ dict (e.g., {'rce_status': result}), preventing Fickling's unused-variable heuristic from flagging the payload.
  3. Verify scanner bypass: Run the crafted pickle file through Fickling (version ≤ 0.1.6) or picklescan; both tools will report the file as LIKELY_SAFE due to the missing blocklist entries for pydoc and ctypes.
  4. Deliver the payload: Distribute the malicious .pkl file through a model repository, file share, or supply chain vector targeting users or automated ML pipelines that use Fickling for safety validation.
  5. Trigger execution: When the victim loads the pickle file (e.g., via pickle.load() or torch.load()), the Pickle VM executes the embedded opcodes, calling WinExec('calc.exe', 1) (or any attacker-chosen command) on the victim's system (GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected .pkl files containing pydoc or ctypes module references when decompiled; files that pass Fickling ≤ 0.1.6 safety checks but contain GLOBAL pydoc locate or GLOBAL ctypes opcodes.
  • Process: Unexpected child processes spawned by Python interpreter during model loading (e.g., calc.exe, cmd.exe, bash, or other OS commands); unusual ctypes-based DLL loads from within a Python process.
  • Logs: Python application logs showing successful pickle deserialization of files that were reported as LIKELY_SAFE by Fickling, followed by unexpected system calls or network activity.
  • Network: Outbound connections from a Python/ML process to unknown external hosts shortly after loading a pickle file, potentially indicating a reverse shell or data exfiltration payload (GitHub Advisory).

Mitigation and workarounds

Upgrade Fickling to version 0.1.7 or later immediately; this release adds ctypes and pydoc to the list of unsafe imports and also checks all components of dotted module paths against the blocklist (GitHub Advisory, Patch Commit). Do not rely solely on Fickling or picklescan as the only security control for untrusted pickle files; implement defense-in-depth by sandboxing pickle deserialization in isolated environments. Avoid loading pickle files from untrusted or unverified sources, particularly in AI/ML pipelines where model weights are fetched from public repositories.

Community reactions

The vulnerability was reported by security researcher 0x-Apollyon and addressed by Trail of Bits maintainer thomas-chauchefoin-tob in a batch fix (PR #195) that resolved five separate security advisories simultaneously (GitHub PR #195). The advisory noted that even competing tools like picklescan share the same blind spot for pydoc.locate, highlighting a broader gap in the pickle security scanning ecosystem. Coverage was picked up by several vulnerability aggregators and security news outlets shortly after disclosure (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management