- A security update has been released for picklescan.
- This update applies to picklescan versions prior to 1.0.4.
- The vulnerability addressed is CVE-2026-53873, which is an arbitrary code execution vulnerability caused by bypassing the
profile.Run() blocklist.
- This vulnerability allows a threat actor to perform arbitrary code execution.
- A Vulnerability Patch is available in the latest update; users must update to version 1.0.4 Or higher.
- Follow the instructions on the reference site to apply the latest version of the Vulnerability Patch.