
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22609 is a static analysis bypass vulnerability in Trail of Bits' Fickling, a Python pickle safety scanner, caused by an incomplete blocklist of dangerous modules. Reported by researcher mldangelo and disclosed on January 9, 2026, it affects all versions of Fickling up to and including v0.1.6 (pip package). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.9 (High) (GitHub Advisory).
The root cause is an incomplete list of disallowed inputs (CWE-184) combined with unsafe deserialization handling (CWE-502). Specifically, the unsafe_imports() method in fickling/fickle.py (lines 866–884) checks imported modules against a hardcoded tuple that omits several high-risk standard library modules: ctypes, importlib, runpy, code, and multiprocessing. Because ctypes is part of the Python standard library, it also bypasses Fickling's NonStandardImports analysis. An attacker can craft a pickle that uses ctypes.pythonapi or ctypes.CDLL to execute arbitrary code, yet the payload passes Fickling's check_safety() returning Severity.LIKELY_SAFE. A minimal proof-of-concept payload is: b'\x80\x04cctypes\npythonapi\n.' (GitHub Advisory, Fix PR #195).
Successful exploitation allows an attacker to achieve arbitrary code execution on any system that loads a malicious pickle file after it has been falsely validated as safe by Fickling. This results in full compromise of confidentiality, integrity, and availability of the affected host. Because Fickling is commonly used in ML/AI pipelines to validate model files (e.g., PyTorch .pkl files), exploitation could affect data science infrastructure, model serving systems, and CI/CD pipelines that rely on Fickling as a security gate (GitHub Advisory).
A proof-of-concept payload is publicly documented in the GitHub Security Advisory itself, demonstrating that a single-line pickle payload bypasses detection. The EPSS score is approximately 0.0018 (low probability of near-term exploitation), and there is no evidence of active in-the-wild exploitation or CISA KEV catalog inclusion as of the time of this report. No threat actor attribution has been identified (GitHub Advisory, Feedly).
ctypes. A minimal example: payload = b'\x80\x04cctypes\npythonapi\n.' — this uses pickle opcode GLOBAL to import ctypes.pythonapi.ctypes.pythonapi or ctypes.CDLL to call arbitrary C functions or execute shell commands (e.g., spawn a reverse shell or exfiltrate data).check_safety() for validation. The scanner returns Severity.LIKELY_SAFE because ctypes is not in the blocklist.pickle.load(), triggering execution of the embedded malicious code with the privileges of the loading process (GitHub Advisory)..pkl, .pickle) that import ctypes, importlib, runpy, code, or multiprocessing modules when decompiled/inspected./bin/sh, curl, wget, or other system utilities).LIKELY_SAFE for files containing ctypes or related module references.Trail of Bits released Fickling v0.1.7, which adds ctypes, importlib, runpy, code, and multiprocessing to the unsafe imports blocklist, and also fixes the detection logic to check all components of dotted module paths (e.g., multiprocessing.util) (Fix PR #195, GitHub Advisory). Users should upgrade immediately via pip install --upgrade fickling. As an interim measure, do not rely solely on Fickling as a security control; supplement with sandboxing (e.g., restricted execution environments), allowlisting of trusted pickle sources, and monitoring of pickle-loading operations.
The vulnerability was disclosed by Trail of Bits' own security team (thomas-chauchefoin-tob) alongside a same-day patch, reflecting responsible internal handling. The fix was part of a broader PR (#195) addressing five related security advisories simultaneously. Community discussion was limited but noted on Bluesky and security aggregator sites shortly after disclosure (GitHub Advisory, Fix PR #195).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."