{"id":"CVE-2025-67748","aliases":["GHSA-r7v6-mfhq-g3m2","PYSEC-2025-113"],"url":"https://o3.security/vulnerability/CVE-2025-67748","summary":"Fickling has Code Injection vulnerability via pty.spawn()","details":"Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.","published":"2025-12-16T00:39:13.968Z","modified":"2026-07-15T01:49:06.344793302Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"fickling","fixedVersion":"0.1.6"}],"fix":{"url":"https://github.com/trailofbits/fickling/pull/108","label":"trailofbits/fickling#108"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67748.json"},{"type":"ADVISORY","url":"https://github.com/trailofbits/fickling/security/advisories/GHSA-r7v6-mfhq-g3m2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67748"},{"type":"FIX","url":"https://github.com/trailofbits/fickling/pull/108"},{"type":"FIX","url":"https://github.com/trailofbits/fickling/pull/187"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:06.344793302Z"}}