Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2025-71341: picklescan up to 0.0.28 can run hidden code
CVE-2025-71341 · published 3 months ago
Summary
The picklescan utility used to examine stored data files may miss a special command that lets attackers hide malicious code inside those files. If a crafted file is opened, the hidden code can run on the system, potentially giving an attacker control. Update picklescan to version 0.0.29 or later, and avoid loading files from unknown sources.
What to do
- Update matthieu maitre picklescan to version 0.0.29.
- Update picklescan to version 0.0.29.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | matthieu maitre | picklescan |
< 0.0.29 Fix: upgrade to 0.0.29
|
| pip | – | picklescan |
< 0.0.29 Fix: upgrade to 0.0.29
|
Original advisory text
picklescan - Remote Code Execution via Undetected profile.Profile.runctx
picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx in the reduce method to achieve remote code execution when the pickle file is loaded.
References
- https://github.com/advisories/GHSA-6vqj-c2q5-j97w Vendor Advisory
- https://github.com/mmaitre314/picklescan/commit/aecd11be98702caa9ba9b12189d91ad5... URL
- https://nvd.nist.gov/vuln/detail/CVE-2025-71341 Vendor Advisory
- https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-undete... Vendor Advisory
- https://github.com/mmaitre314/picklescan/security/advisories/GHSA-6vqj-c2q5-j97w Vendor Advisory
- https://github.com/mmaitre314/picklescan Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71341... Vendor Advisory
- https://pypi.org/project/picklescan Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published23 Jun 2026
Updated2 Oct 2026
First seen6 Mar 2026
Sources
GHSA-6vqj-c2q5-j97w · GHSA
CVE-2025-71341 · NVD
GHSA-6vqj-c2q5-j97w · OSV
PYSEC-2026-4132 · OSV
CVE-2025-71341 · OSV
Track software like this
Free during beta