PT-2026-55672 · Pypi · Picklescan

·

CVE-2025-71359

·

Published

2025-08-26

·

Updated

2026-07-04

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions picklescan versions prior to 0.0.29
Description The software fails to detect malicious pickle payloads that utilize the lib2to3.pgen2.grammar.Grammar.loads function within the reduce method. This flaw allows remote code execution, as attackers can craft pickle files containing dangerous code that evades detection and executes during the pickle.load() deserialization process. Deserialization is the process of converting a data format back into an object.
Recommendations Update to version 0.0.29 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71359
GHSA-F54Q-57X4-JG88

Affected Products

Picklescan