CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-69872

Critical · CVSS 9.8

python-diskcache (DiskCache) — Pickle deserialization arbitrary code execution (CWE-94, CWE-502)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-94, CWE-502

Description

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

Search profile — drives PoC discovery

Symbols picklediskcacheCacheFanoutCacheDiskCachedisk.getdisk.putpickle.loadspickle.dumpsEVICTION_POLICYcache.getcache.set__reduce__
Keywords CVE-2025-69872diskcache pickle deserializationpython-diskcache RCEdiskcache arbitrary code executiondiskcache pickle exploitdiskcache cache directory writediskcache 5.6.3 vulnerabilityEthanKim88 diskcachegrantjenks python-diskcache CVE
Versions: through 5.6.3

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z