PT-2026-54008 · Unknown+1 · Picklescan+1

·

CVE-2025-71355

·

Published

2025-04-07

·

Updated

2026-07-01

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Picklescan versions prior to 0.0.25
Description Picklescan fails to detect unsafe global functions within the Numpy library, which allows attackers to bypass static analysis. This issue enables the execution of arbitrary code during deserialization. An attacker can create malicious pickle files using the numpy.testing. private.utils.runstring function within the reduce method to import dangerous libraries, such as os, and execute arbitrary operating system commands when the file is loaded.
Recommendations Update Picklescan to version 0.0.25 or later.

Exploit

Fix

Incomplete List of Disallowed Inputs

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71355
GHSA-FJ43-3QMQ-673F

Affected Products

Numpy
Picklescan