HIGH8.8
PYSEC-2026-1939
sqlitedict insecure deserialization vulnerability
Details
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/sqlitedict
Introduced in:
0No fixed version published yet for sqlitedict (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-35515[ADVISORY]
- https://github.com/piskvorky/sqlitedict/issues/174[WEB]
- https://github.com/piskvorky/sqlitedict[PACKAGE]
- https://github.com/piskvorky/sqlitedict?tab=readme-ov-file#serialization[WEB]
- https://wha13.github.io/2024/06/13/mfcve[WEB]
- https://pypi.org/project/sqlitedict[PACKAGE]
- https://github.com/advisories/GHSA-g4r7-86gm-pgqc[ADVISORY]