VendorsTrail of Bitsficklingall versions
Vulnerabilities

Trail of Bits Fickling

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-14535
Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()
Published 2026-07-04 · Analyzed
9.8EPSS 0.006
CVE-2026-22609
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
Published 2026-01-10 · Analyzed
8.9EPSS 0.006
CVE-2026-22607
Fickling Blocklist Bypass: cProfile.run()
Published 2026-01-10 · Analyzed
8.9EPSS 0.005
CVE-2026-22606
Fickling has a bypass via runpy.run_path() and runpy.run_module()
Published 2026-01-10 · Analyzed
8.9EPSS 0.005
CVE-2026-22608
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
Published 2026-01-10 · Analyzed
8.9EPSS 0.004
CVE-2026-22612
Fickling vulnerable to detection bypass due to "builtins" blindness
Published 2026-01-10 · Analyzed
8.9EPSS 0.003
CVE-2026-14534
Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)
Published 2026-07-04 · Analyzed
8.8EPSS 0.006
CVE-2025-67747
Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
Published 2025-12-16 · Analyzed
7.8EPSS 0.003
CVE-2025-67748
Fickling has Code Injection vulnerability via pty.spawn()
Published 2025-12-16 · Analyzed
7.8EPSS 0.003