CVE-2025-56005 affects the PyPI-distributed PLY (Python Lex-Yacc) 3.11 package. The undocumented picklefile argument to ply.yacc.yacc() causes LRTable.read_pickle() to deserialize the referenced parser-table file using Python's pickle.load() without validation. A pickle payload can invoke attacker-selected behavior during deserialization, including through __reduce__(), resulting in code execution during parser initialization before parsing begins. The applicability of the published proof of concept and the CVE's classification have been disputed; however, loading an attacker-controlled Python pickle through this code path is inherently unsafe.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
yacc(picklefile=...) can execute code with the privileges of the process running PLY. This may compromise confidentiality, integrity, and availability, and can enable persistence or backdoor deployment where parser-table files are loaded from shared, cached, configurable, or externally writable locations.If you can’t patch tonight, do this now.
picklefile functionality with untrusted data. Ensure parser-table locations are not user-controlled or writable by untrusted principals; enforce ownership and permissions on cache, build, and shared directories; and prevent CI/CD or deployment workflows from accepting serialized parser tables from untrusted artifacts. Treat all Python pickle content as executable and untrusted by default.Patch, then assume compromise.
picklefile and regenerate parser tables rather than loading serialized tables from disk.2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This eight-file repository is a self-contained Docker reproduction harness for CVE-2025-56005 in PLY 3.11. The Python attacker program serializes an object whose __reduce__ method requests os.system execution and writes it as a malicious parser-table pickle. The Python victim program subsequently calls ply.yacc.yacc(picklefile=TABLE), causing vulnerable PLY to pickle.load the attacker-controlled file and execute the command in the victim process context. The hard-coded demonstration command only creates a PWNED_PROOF marker containing the victim username and timestamp. Docker Compose models the required trust boundary with separate attacker and victim containers, an unprivileged victim user, a shared named volume, and network_mode: none; the attacker is limited to writing /shared/parsetab.pkl. Dockerfile, Makefile, and run_demo.sh support vulnerable ('before') and hardened-fork ('after') comparisons. The hardened fork is expected to reject pickle globals before command execution. No external endpoint is contacted during runtime, although builds may install the hardened fork from its GitHub URL.
Repository purpose: a small Python project intended to reproduce and critique an alleged PLY 3.11 RCE (referenced as CVE-2025-56005) and argue for rejection. Structure: README.md explains that the copied PoC in main.py fails (AttributeError) and does not demonstrate cross-process untrusted data flow; main.py contains the only code. Exploit mechanics in main.py: it crafts a dictionary mimicking PLY yacc parsing tables and embeds an object (Exploit) whose __reduce__ returns (os.system, (cmd,)), then pickles this structure to a local file exploit.pkl. It then calls ply.yacc.yacc(picklefile='exploit.pkl', debug=False, write_tables=False) and parses the token 'example'. If PLY unpickles attacker-controlled parser tables unsafely, unpickling would execute the payload command, creating /tmp/pwned and writing 'VULNERABLE'. No network exploitation is implemented; the attack vector is local and depends on a victim process loading an attacker-supplied picklefile. The repository includes pyproject.toml and uv.lock to pin ply==3.11 and provide reproducible setup via uv.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability tracked as CVE-2025-56005 affecting the python-ply-help and python3-ply packages on Huawei EulerOS 2.11.1.
A vulnerability tracked as CVE-2025-56005 affecting the python-ply-help and python3-ply packages on Huawei EulerOS 2.11.0.
Unknown (listed as a trending CVE affecting PLY; no technical details provided in the content).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.