A critical remote code execution (RCE) vulnerability was disclosed in the PyPI-distributed PLY (Python Lex-Yacc) 3.11 library, tracked as CVE-2025-56005 (reported with CVSS 9.8). The issue stems from an undocumented picklefile parameter in yacc() that triggers pickle.load() on an attacker-controlled file without validation, enabling arbitrary code execution during deserialization (e.g., via __reduce__()) before parser initialization completes. Reporting noted the risk is amplified because execution can occur silently at application startup, prior to any parsing logic.
Exploitation is feasible in environments where parser tables or build artifacts are cached or shared, including cached parser table locations, shared network directories, and CI/CD pipeline artifacts, if an attacker can influence or replace the referenced pickle file or its path. A proof-of-concept was described demonstrating that a crafted pickle can execute system commands as soon as yacc(picklefile=...) is invoked. Separately, a different Python ecosystem issue was also reported: CVE-2026-0994 in Google Protocol Buffers Python JSON parsing (google.protobuf.json_format.ParseDict()), where nested google.protobuf.Any messages can bypass recursion-depth accounting and crash services via DoS—but this is unrelated to the PLY RCE.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The vulnerability was publicly documented as CVE-2025-56005 with a CVSS score of 9.8, and reporting described a proof of concept showing system command execution during parser initialization. Public guidance advised users to avoid the `picklefile` parameter, audit code paths influencing `yacc()` arguments, and treat related pickle files as untrusted.
Security researcher Bohmiiidd identified a critical remote code execution flaw in the PyPI-distributed PLY 3.11 package. The issue stems from an undocumented `picklefile` parameter in `yacc()` that deserializes attacker-controlled data with `pickle.load()` without validation.
The PLY (Python Lex-Yacc) project's maintainer announced that the library was being abandoned, leaving the package without expected future maintenance. This set the context for later concern that no official fix would likely be issued for newly found flaws.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.