CVE-2025-70559: Insecure Path Join Pickle Loads

Path traversal leading to insecure deserialization. Using `os.path.join` with uncontrolled inputs and passing the result directly to an `open` call before deserializing with `pickle.loads` allows attackers to bypass boundary checks and execute arbitrary code. Validate paths using `os.path.realpath` and verify directory prefixes before opening.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2025-70559-insecure-path-join-pickle-loads --engine opengrep

Description

Path traversal leading to insecure deserialization. Using `os.path.join` with uncontrolled inputs and passing the result directly to an `open` call before deserializing with `pickle.loads` allows attackers to bypass boundary checks and execute arbitrary code. Validate paths using `os.path.realpath` and verify directory prefixes before opening.