LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-3490

Published
CVSS10
Severitycritical
WeaknessCWE-183
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.system, builtins.exec, or subprocess.call to achieve remote code execution.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-3490

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-3490.