fickling vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-5CXW-W2XG-2M8HMediumfickling: fickling's `platform` module subprocess invocation evades `check_safety()` with `LIKELY_SAFE`GHSA-R48F-3986-4F9CMediumfickling: fickling modules linecache, difflib and gc are missing from the unsafe modules blocklistGHSA-5HWF-RC88-82XMHighfickling: Fickling missing RCE-capable modules in UNSAFE_IMPORTSGHSA-WCCX-J62J-R448Highfickling: Fickling has `always_check_safety()` bypass: pickle.loads and _pickle.loads remain unhookedGHSA-MHC9-48GJ-9GP3Mediumfickling: Fickling has safety check bypass via REDUCE+BUILD opcode sequenceGHSA-MXHJ-88FX-4PCVHighfickling: Fickling: OBJ opcode call invisibility bypasses all safety checksGHSA-83PF-V6QQ-PWMRLowfickling: Fickling has a detection bypass via stdlib network-protocol constructorsCVE-2026-22612Highfickling: Fickling vulnerable to detection bypass due to "builtins" blindnessCVE-2026-22609Highfickling: Fickling has Static Analysis Bypass via Incomplete Dangerous Module BlocklistCVE-2026-22608Highfickling: Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detectionCVE-2026-22607Highfickling: Fickling Blocklist Bypass: cProfile.run()CVE-2026-22606Highfickling: Fickling has a bypass via runpy.run_path() and runpy.run_module()CVE-2025-67748Highfickling: Fickling has Code Injection vulnerability via pty.spawn()CVE-2025-67747Highfickling: Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list

Stop the waste.
Protect your environment with Kodem.