Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. fickling
  4. ›
  5. CVE-2025-67747

CVE-2025-67747: Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list

December 15, 2025 (updated December 20, 2025)

There’s missing detection for the python modules, marshal.loads and types.FunctionType and Fickling throws unhandled ValueErrors when the stack is deliberately exhausted.

References

  • github.com/advisories/GHSA-565g-hwwr-4pp3
  • github.com/trailofbits/fickling
  • github.com/trailofbits/fickling/commit/4e34561301bda1450268d1d7b0b2b151de33b913
  • github.com/trailofbits/fickling/pull/186
  • github.com/trailofbits/fickling/releases/tag/v0.1.6
  • github.com/trailofbits/fickling/security/advisories/GHSA-565g-hwwr-4pp3
  • nvd.nist.gov/vuln/detail/CVE-2025-67747

Code Behaviors & Features

Detect and mitigate CVE-2025-67747 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.1.6

Fixed versions

  • 0.1.6

Solution

Upgrade to version 0.1.6 or above.

Impact 7.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-184: Incomplete List of Disallowed Inputs
  • CWE-502: Deserialization of Untrusted Data

Source file

pypi/fickling/CVE-2025-67747.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 04 Feb 2026 00:35:13 +0000.