CVE-2026-14535 Details
Description
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call registers the shortened code representation in the shared AnalysisContext.reported_shortened_code set. When the MLAllowlist analysis pass subsequently runs, it calls the same shorten_code() method, receives already_reported=True for every import, and executes a continue statement that skips its allowlist check entirely. This renders MLAllowlist dead code for all imports — it never evaluates whether an import is in the ML allowlist or not. The MLAllowlist pass was designed to catch imports of modules outside the known-safe ML ecosystem (torch, numpy, transformers, etc.) that slip past the UnsafeImports denylist. With MLAllowlist inoperative, any standard library module not in the UNSAFE_IMPORTS denylist can be invoked via pickle deserialization while fickling's check_safety() returns LIKELY_SAFE. The fickling.load() API chains check_safety() into pickle.loads() as an explicit security gate, meaning a LIKELY_SAFE verdict causes the payload to be deserialized and executed. The root cause is shared mutable state between independently-correct analysis passes — UnsafeImportsML works as designed in isolation, MLAllowlist works as designed in isolation, but the shared reported_shortened_code set causes UnsafeImportsML to poison MLAllowlist's deduplication logic.
A vulnerability exists in Trail of Bits Fickling versions through 0.1.11, where the MLAllowlist analysis pass is rendered ineffective due to an unintentional interaction with the UnsafeImportsML pass. The issue arises because UnsafeImportsML processes all import nodes and registers them as 'shortened' in a shared context, regardless of their safety status. When MLAllowlist runs afterward, it finds all imports marked as 'already reported' and skips its safety checks, allowing potentially unsafe standard library modules to be used via pickle deserialization. This flaw exploits the shared mutable state between the two analysis passes, causing MLAllowlist to overlook imports that should be flagged.
Users can update to Fickling version 0.1.12 or later, where this vulnerability has been fixed. After updating, it's important to pass the MLAllowlist analysis into the check_safety() function to ensure proper import validation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/trailofbits/fickling/security/advisories/GHSA-cffv-grgg-g429 | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/trailofbits/fickling/commit/41ce7cb01edd97072994039574a2301ebb3f463d | BombadilSystems | Patch |
| https://github.com/trailofbits/fickling/pull/278 | BombadilSystems | Issue TrackingPatch |
| https://github.com/trailofbits/fickling/releases/tag/v0.1.12 | BombadilSystems | Release Notes |
| https://github.com/trailofbits/fickling/security/advisories/GHSA-cffv-grgg-g429 | BombadilSystems | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | BombadilSystems |
Affected Products
| Product | Versions |
|---|---|
| trailofbits fickling | <= 0.1.11 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 4, 2026 | New CVE Received | BombadilSystems |