PT-2026-55679 · Pypi · Picklescan

·

CVE-2025-71372

·

Published

2025-12-30

·

Updated

2026-07-07

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions Picklescan versions prior to 0.0.33
Description Picklescan fails to detect the numpy.f2py.crackfortran.getlincoef gadget within pickle reduce methods. This allows attackers to craft malicious pickle files that execute arbitrary Python code upon loading, bypassing safety checks and enabling supply-chain poisoning of shared model files.
Recommendations Update Picklescan to version 0.0.33 or later.

Exploit

Fix

Code Injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71372
GHSA-RRXM-2PVV-M66X

Affected Products

Picklescan