PT-2026-51385 · Pypi · Picklescan

·

CVE-2025-71358

·

Published

2025-08-26

·

Updated

2026-07-07

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions picklescan versions prior to 0.0.29
Description An issue exists where the software fails to detect malicious pickle files that utilize the get entity() function within the idlelib.autocomplete.AutoComplete module in reduce methods. This allows attackers to embed undetected code in pickle files that executes arbitrary commands when loaded by victims using the pickle.load() function. This can lead to remote code execution, potentially affecting organizations or individuals using the tool to scan PyTorch models, APIs, or saved Python objects.
Recommendations Update to version 0.0.29 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71358
GHSA-6W4W-5W54-RJVR
PYSEC-2026-1784

Affected Products

Picklescan