CVE-2025-67748·Python vulnerability
Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.
- Severity
- high
- Software
- Python
- Fixed in
- 0.1.6
- Published
- 2025-12-16
Affected versions
Until: 0.1.6
Fixed in: 0.1.6
How to fix this CVE
Update Fickling to version 0.1.6 or later to resolve the module validation bypass. This vulnerability allowed attackers to craft pickle files that evaded security checks by exploiting a missing `pty` module in the unsafe imports blocklist. Organizations relying on Fickling for pickle file vetting should prioritize this update to restore proper detection of malicious serialized objects.
sudo dnf install -y python3-pip && pip3 install --upgrade ficklingDefensia detects this vulnerability
How to check if you are affected
- Check Fickling version: pip3 show fickling | grep Version
- Verify if Fickling is used in your environment: grep -r 'from fickling' /path/to/application --include='*.py' || grep -r 'import fickling' /path/to/application --include='*.py'
- Review application logs for pickle deserialization or validation events, particularly those involving `pty.spawn()` calls or subprocess execution triggered by serialized objects
- After upgrade, confirm the new version: pip3 show fickling | grep Version (should be 0.1.6 or higher)
FAQ
What is CVE-2025-67748?
CVE-2025-67748 is a security bypass in Fickling versions before 0.1.6 where the `pty` module was omitted from the unsafe module blocklist, allowing malicious pickle files using `pty.spawn()` to be incorrectly classified as safe during static analysis.
Is CVE-2025-67748 being actively exploited?
No, according to CISA's Known Exploited Vulnerabilities catalog, CVE-2025-67748 is not currently being actively exploited in the wild, and no public exploit code is available.
What versions of Python are affected by CVE-2025-67748?
The vulnerability affects Fickling library versions prior to 0.1.6, regardless of the underlying Python version. Any environment running Fickling < 0.1.6 for pickle security analysis is at risk.
How do I check if my server is vulnerable to CVE-2025-67748?
Run `pip3 show fickling` and check the Version field. If the version is below 0.1.6, your installation is vulnerable. If Fickling is not installed, you are not affected by this vulnerability.
Does Defensia detect CVE-2025-67748?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Fickling is installed on a monitored server, CVE-2025-67748 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-67748. Free for 1 server.
Get started free