PT-2025-55498 · Pypi · Picklescan
Publicado
2025-12-30
·
Atualizado
2025-12-30
CVSS v4.0
8.2
Alta
| Vetor | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
Summary
Picklescan uses the
numpy.f2py.crackfortran.getlincoef function (a NumPy F2PY helper) to execute arbitrary Python code during unpickling.Details
Picklescan fails to detect a malicious pickle that uses the gadget
numpy.f2py.crackfortran.getlincoef in reduce, allowing arbitrary command execution when the pickle is loaded. A crafted object returns this function plus attacker‑controlled arguments; the scan reports the file as safe, but pickle.load() triggers execution.PoC
python
class PoC:
def reduce (self):
from numpy.f2py.crackfortran import getlincoef
return getlincoef, (" import ('os').system('whoami')", None)Impact
- Arbitrary code execution on the victim machine once they load the “scanned as safe” pickle / model file.
- Affects any workflow relying on Picklescan to vet untrusted pickle / PyTorch artifacts.
- Enables supply‑chain poisoning of shared model files.
Credits
Correção
Deserialization of Untrusted Data
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Picklescan