Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2025-71341: picklescan up to 0.0.28 can run hidden code

CVE-2025-71341 · published 3 months ago
Summary

The picklescan utility used to examine stored data files may miss a special command that lets attackers hide malicious code inside those files. If a crafted file is opened, the hidden code can run on the system, potentially giving an attacker control. Update picklescan to version 0.0.29 or later, and avoid loading files from unknown sources.

What to do
  • Update matthieu maitre picklescan to version 0.0.29.
  • Update picklescan to version 0.0.29.
Affected software
Ecosystem VendorProductAffected versions
pip matthieu maitre picklescan < 0.0.29
Fix: upgrade to 0.0.29
pip – picklescan < 0.0.29
Fix: upgrade to 0.0.29
Original advisory text
picklescan - Remote Code Execution via Undetected profile.Profile.runctx
picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx in the reduce method to achieve remote code execution when the pickle file is loaded.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published23 Jun 2026
Updated2 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta