VDB
DEBIAN-CVE-2025-69872
DEBIAN-CVE-2025-69872
PUBLISHED
CVSS 9.800000190734863 CRITICAL
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | diskcache | 5.6.3-1, 0, 5.6.3-1 |
| Debian:12 | diskcache | 5.4.0-3, 5.4.0-1, 5.4.0-1 |
| Debian:11 | diskcache | 5.4.0-2, 0, 5.4.0-1 |
| Debian:14 | diskcache | 5.6.3-1, 5.6.3-1, 0 |
Exploit Intelligence
- releases.json (github-poc)
- test_security_audit.py (github-poc)
- test_cycle34_release_hygiene.py (github-poc)
- hook_executor.py (github-poc)
- tool_commands.py (github-poc)
Timeline
- Feb 11, 2026 CVE Published
- Apr 28, 2026 CVE Updated