CVE-2026-53872: Picklescan
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read arbitrary server files by chaining io.FileIO and urllib.request.urlopen. Attackers can bypass RCE-focused blocklists to exfiltrate sensitive data like /etc/passwd to external servers.
Affected products
- Picklescan Picklescan: before 0.0.35 (fixed in 0.0.35)
Published 2026-06-17. Last modified 2026-06-17.