All 7 CVE vulnerabilities found in fickling, with AI-generated Chinese analysis, references, and POCs.
Vendor: trailofbits
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-22612 | Fickling vulnerable to detection bypass due to "builtins" blindness CWE-502 | 9.1 | - | 2026-01-10 |
| CVE-2026-22609 | Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist CWE-184 | 9.8 | - | 2026-01-10 |
| CVE-2026-22608 | Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection CWE-184 | 9.8 | - | 2026-01-10 |
| CVE-2026-22607 | Fickling Blocklist Bypass: cProfile.run() CWE-184 | 9.8 | - | 2026-01-10 |
| CVE-2026-22606 | Fickling has a bypass via runpy.run_path() and runpy.run_module() CWE-184 | 9.8 | - | 2026-01-10 |
| CVE-2025-67748 | Fickling has Code Injection vulnerability via pty.spawn() CWE-184 | 9.1AI | CriticalAI | 2025-12-16 |
| CVE-2025-67747 | Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list CWE-184 | 8.4AI | HighAI | 2025-12-16 |
All 7 known CVE vulnerabilities affecting fickling with full Chinese analysis, references, and POCs where available.