
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22612 is a detection bypass vulnerability in Fickling, a Python pickling decompiler and static analyzer developed by Trail of Bits. The flaw, dubbed "builtins blindness," allows attackers to craft malicious pickle files that evade Fickling's security analysis by exploiting the tool's failure to emit AST import nodes for Python's builtins module. All versions prior to 0.1.7 are affected. It was disclosed on January 9–10, 2026, and carries a CVSS v3.1 score of 7.8 (High) and a CVSS v4.0 score of 8.9 (High) (GitHub Advisory).
The root cause (CWE-502: Deserialization of Untrusted Data) lies in fickling/fickle.py, where the run() method of the Global opcode handler explicitly skipped emitting AST ImportFrom nodes when the module was __builtin__, __builtins__, or builtins. Because Fickling's security analysis operates on the generated AST rather than raw bytecode, imports from builtins — including dangerous functions like __import__ and getattr — were invisible to the scanner. An attacker could craft a pickle payload that uses builtins.__import__ to load os, then builtins.getattr to retrieve os.system, and execute arbitrary commands, while Fickling's analysis classified the payload as LIKELY_SAFE. A secondary technique using the BUILD opcode satisfied data-flow liveness checks, further preventing detection (GitHub Advisory, Patch Commit).
Successful exploitation allows an attacker to bypass Fickling's security validation and deliver malicious pickle payloads to systems that rely on Fickling to screen untrusted serialized Python objects. Once a malicious pickle is loaded by the target application, arbitrary code execution is achievable, leading to full compromise of confidentiality, integrity, and availability of the affected system. This is particularly dangerous in ML/AI pipelines and data processing workflows where pickle files from untrusted sources are routinely scanned with tools like Fickling before being deserialized (GitHub Advisory).
A proof-of-concept payload generator (poc.py) is publicly documented in the GitHub security advisory, demonstrating how to craft a raw_bypass.pkl file that executes arbitrary OS commands while being classified as LIKELY_SAFE by vulnerable Fickling versions. There is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.043%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
GLOBAL opcodes referencing builtins.__import__ and builtins.getattr to load os.system without triggering Fickling's import detection.BUILD opcode to incorporate the result of os.system() (the exit code) into a returned Exception object's state, creating a logical dependency chain that satisfies Fickling's liveness heuristics and prevents "UNUSED" variable warnings.raw_bypass.pkl file to a system or pipeline that uses a vulnerable version of Fickling (< 0.1.7) to validate pickle files before deserialization. Fickling will classify the payload as LIKELY_SAFE.os.system('whoami') (or any attacker-chosen command) with the privileges of the application process (GitHub Advisory)..pkl files containing builtins\n__import__\n or builtins\ngetattr\n byte sequences in raw form; unexpected pickle files classified as LIKELY_SAFE by Fickling that reference os, subprocess, or other sensitive modules.LIKELY_SAFE for files that subsequently trigger anomalous behavior.sh, bash, cmd.exe, whoami, curl, wget) immediately after pickle deserialization events.Upgrade Fickling to version 0.1.7 or later, which fixes the issue by removing the special-case exclusion for builtins imports and ensuring AST ImportFrom nodes are emitted for all modules, including builtins (Patch Commit, v0.1.7 Release). If immediate patching is not possible, avoid using Fickling to validate untrusted pickle files and restrict access to any pipeline that deserializes externally sourced pickle data. Additionally, review any systems that processed untrusted pickle files with vulnerable Fickling versions for signs of compromise.
The vulnerability was reported by security researcher 0x-Apollyon and acknowledged by Trail of Bits maintainer thomas-chauchefoin-tob, who published the advisory and patch on January 9, 2026. The fix was bundled with four other bypass fixes in the v0.1.7 release, indicating a broader security review of Fickling's analysis pipeline (v0.1.7 Release). No significant broader media coverage or social media discussion beyond the GitHub advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."