CVE-2026-14534 Details
Description
Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with zero findings for pickle payloads that invoke dangerous functions including _posixsubprocess.fork_exec (C-level process spawner capable of executing arbitrary binaries), site.execsitecustomize (executes arbitrary site customization code), and atexit._run_exitfuncs (triggers all registered exit handler callbacks). The fickling.load() API chains check_safety() into pickle.loads() as an explicit security gate; a LIKELY_SAFE verdict causes the payload to be deserialized and executed. This shares the same root cause as CVE-2026-22607 (cProfile), CVE-2025-67748 (pty), and CVE-2025-67747 (marshal/types). OvertlyBadEvals does not flag these modules because they are standard library imports. UnsafeImports does not flag them because they are not in the denylist. The UnusedVariables heuristic is defeated by the SETITEMS opcode pattern.
A vulnerability in the Trail of Bits Fickling library, affecting versions through 0.1.10, allows for a bypass of the safety check in the pickle loading process. The issue arises because certain Python standard library modules, specifically '_posixsubprocess', 'site', and 'atexit', are not included in the UNSAFE_IMPORTS denylist. This omission enables pickle payloads to invoke functions that can execute arbitrary code or commands, such as spawning processes at the C level, executing site customization code, or triggering registered exit handler callbacks. The vulnerability is rooted in the same issue as several other known vulnerabilities, where standard library imports are not properly flagged as unsafe.
Users can upgrade to Fickling version 0.1.11 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/trailofbits/fickling/security/advisories/GHSA-m6fh-58r7-x697 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/trailofbits/fickling/commit/e8408615b63adf034f891f653692ab9b51f0f5af | BombadilSystems | Patch |
| https://github.com/trailofbits/fickling/pull/272 | BombadilSystems | Issue TrackingPatch |
| https://github.com/trailofbits/fickling/releases/tag/v0.1.11 | BombadilSystems | Release Notes |
| https://github.com/trailofbits/fickling/security/advisories/GHSA-m6fh-58r7-x697 | BombadilSystems | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-184 | Incomplete List of Disallowed Inputs | BombadilSystems |
| CWE-502 | Deserialization of Untrusted Data | BombadilSystems |
Affected Products
| Product | Versions |
|---|---|
| trailofbits fickling | <= 0.1.10 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 4, 2026 | New CVE Received | BombadilSystems |