PT-2026-50453 · Pypi · Picklescan
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PickleScan versions prior to 0.0.33
Description
PickleScan fails to include the
pty.spawn function in its list of unsafe globals, which allows attackers to bypass security checks. By crafting malicious pickle payloads using the pty.spawn function, an attacker can achieve arbitrary code execution when files, such as PyTorch models or ZIP archives, are processed by the software.Recommendations
Update to version 0.0.33 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Picklescan