PT-2026-51384 · Pypi · Picklescan

·

CVE-2025-71344

·

Published

2025-08-26

·

Updated

2026-07-07

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions picklescan versions 0.0.26 and earlier
Description The software fails to detect the ensurepip. run pip built-in function when scanning pickle files. Attackers can craft malicious pickle files by embedding calls to ensurepip. run pip within reduce methods, allowing them to bypass detection. When a user invokes pickle.load() on such a file after it has been incorrectly flagged as safe, it can lead to remote code execution. This issue impacts organizations or individuals using the tool to detect malicious pickle files within PyTorch models, potentially enabling supply chain attacks through infected ML models, APIs, or saved Python objects.
Recommendations Update to version 0.0.30 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71344
GHSA-XP4F-HRF8-RXW7
PYSEC-2026-1792

Affected Products

Picklescan