CVE-2026-56315
CRITICALpicklescan - Remote Code Execution via Unblocked Standard Library Modules
Title source: cnaDescription
picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attackers can craft malicious pickle files importing these unblocked modules to achieve remote code execution while bypassing picklescan's safety validation entirely.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-g38g-8gr9-h9xp)
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-g38g-8gr9-h9xp
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Remote Code Execution via Unblocked Standard Library Modules
https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-unblocked-standard-library-modules
Scores
CVSS v3
9.8
EPSS
0.0076
EPSS Percentile
51.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-184
Status
published
Products (2)
picklescan/picklescan
< 1.0.4
picklescan/picklescan
1.0.4
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026