CRITICAL9.8CVE-2026-14535In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shor… from 0, < 0.1.12
HIGH8.8CVE-2026-14534Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and a… from 0, < 0.1.11
HIGH7.8CVE-2025-67748Fickling has Code Injection vulnerability via pty.spawn() from 0, < 0.1.6
HIGH7.8Fickling has Code Injection vulnerability via pty.spawn()
from 0, < 0.1.6
—Fickling vulnerable to detection bypass due to "builtins" blindness
from 0, < 0.1.7
—Fickling vulnerable to detection bypass due to "builtins" blindness
from 0, < 0.1.7
—Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
from 0, < 0.1.7
—Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
from 0, < 0.1.7
—Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
from 0, < 0.1.7
—Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
from 0, < 0.1.7
—Fickling Blocklist Bypass: cProfile.run()
from 0, < 0.1.7
—Fickling Blocklist Bypass: cProfile.run()
from 0, < 0.1.7
—Fickling has a bypass via runpy.run_path() and runpy.run_module()
from 0, < 0.1.7
—Fickling has a bypass via runpy.run_path() and runpy.run_module()
from 0, < 0.1.7
—Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
from 0, < 0.1.6
—Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
from 0, < 0.1.6