CVE-2025-56005

EUVD-2026-3342
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows execution of embedded code via `__reduce__()`, an attacker can achieve code execution by passing a malicious pickle file. The parameter is not mentioned in official documentation or the GitHub repository, yet it is active in the PyPI version. This introduces a stealthy backdoor and persistence risk. NOTE: A third-party states that this vulnerability should be rejected because the proof of concept does not demonstrate arbitrary code execution and fails to complete successfully.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
dabeazply
3.11
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ply
bookworm
unimportant
bullseye
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
policycoreutils
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-dbus
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-debuginfo
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-debugsource
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-devel
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-devel-debuginfo
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-gui
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-newrole
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-newrole-debuginfo
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-python-utils
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-restorecond
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
policycoreutils-restorecond-debuginfo
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed
python3-policycoreutils
Amazon Linux 2023
0:3.4-6.amzn2023.0.3
fixed