PT-2026-51217 · Pypi · Picklescan

·

CVE-2025-71378

·

Published

2025-08-26

·

Updated

2026-06-26

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions picklescan versions prior to 0.0.30
Description The software fails to detect cProfile.runctx function calls within pickle file reduce methods. This allows attackers to bypass detection and execute arbitrary code when malicious pickle files are loaded via pickle.load().
Recommendations Update to version 0.0.30 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71378
GHSA-9W88-8RMG-7G2P
GHSA-FCQG-3MWF-CFCF
PYSEC-2026-247

Affected Products

Picklescan