Description
picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files that execute arbitrary code when loaded via pickle.load().
Problem types
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Product status
Any version before 0.0.29
0.0.29 (semver)
Credits
FredericDT
References
github.com/...lescan/security/advisories/GHSA-8r4j-24qv-fmq9
github.com/...lescan/security/advisories/GHSA-8r4j-24qv-fmq9 (GitHub Security Advisory (GHSA-8r4j-24qv-fmq9))
www.vulncheck.com/...ected-idlelib-calltip-calltip-fetch-tip (VulnCheck Advisory: picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fetch_tip)